CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25584  CVE-2007-2227  Candidate  The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition "notifications," which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "Content Disposition Parsing Cross Domain Information Disclosure Vulnerability."  Assigned (20070424)  None (candidate not yet proposed)    View
91120  CVE-2016-4301  Candidate  Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file.  Assigned (20160427)  None (candidate not yet proposed)    View
25840  CVE-2007-2483  Candidate  Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the wpPATH parameter.  Assigned (20070503)  None (candidate not yet proposed)    View
91376  CVE-2016-4557  Candidate  The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data structure, which allows local users to gain privileges or cause a denial of service (use-after-free) via crafted BPF instructions that reference an incorrect file descriptor.  Assigned (20160506)  None (candidate not yet proposed)    View
26096  CVE-2007-2739  Candidate  Cross-site scripting (XSS) vulnerability in xajax before 0.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20070517)  None (candidate not yet proposed)    View

Page 19709 of 20943, showing 5 records out of 104715 total, starting on record 98541, ending on 98545

Actions