CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
91632 | CVE-2016-4813 | Candidate | NetCommons 2.4.2.1 and earlier allows remote authenticated secretariat (aka CLERK) users to gain privileges by creating a SYSTEM_ADMIN account. | Assigned (20160517) | None (candidate not yet proposed) | View | |
26352 | CVE-2007-2995 | Candidate | Unspecified vulnerability in sysmgt.websm.rte in IBM AIX 5.2.0 and 5.3.0 has unknown impact and attack vectors. | Assigned (20070604) | None (candidate not yet proposed) | View | |
91888 | CVE-2016-5069 | Candidate | Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL. | Assigned (20160526) | None (candidate not yet proposed) | View | |
26608 | CVE-2007-3251 | Candidate | Multiple directory traversal vulnerabilities in e-Vision CMS 2.02 and earlier allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the adminlang cookie to admin/functions.php or (2) read arbitrary local files via the img parameter to admin/show_img.php. | Assigned (20070618) | None (candidate not yet proposed) | View | |
92144 | CVE-2016-5325 | Candidate | CRLF injection vulnerability in the ServerResponse#writeHead function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the reason argument. | Assigned (20160607) | None (candidate not yet proposed) | View |
Page 19709 of 20943, showing 5 records out of 104715 total, starting on record 98541, ending on 98545