CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
25584 | CVE-2007-2227 | Candidate | The MHTML protocol handler in Microsoft Outlook Express 6 and Windows Mail in Windows Vista does not properly handle Content-Disposition "notifications," which allows remote attackers to obtain sensitive information from other Internet Explorer domains, aka "Content Disposition Parsing Cross Domain Information Disclosure Vulnerability." | Assigned (20070424) | None (candidate not yet proposed) | View | |
91120 | CVE-2016-4301 | Candidate | Stack-based buffer overflow in the parse_device function in archive_read_support_format_mtree.c in libarchive before 3.2.1 allows remote attackers to execute arbitrary code via a crafted mtree file. | Assigned (20160427) | None (candidate not yet proposed) | View | |
25840 | CVE-2007-2483 | Candidate | Directory traversal vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the wpPATH parameter. | Assigned (20070503) | None (candidate not yet proposed) | View | |
91376 | CVE-2016-4557 | Candidate | The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly maintain an fd data structure, which allows local users to gain privileges or cause a denial of service (use-after-free) via crafted BPF instructions that reference an incorrect file descriptor. | Assigned (20160506) | None (candidate not yet proposed) | View | |
26096 | CVE-2007-2739 | Candidate | Cross-site scripting (XSS) vulnerability in xajax before 0.2.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20070517) | None (candidate not yet proposed) | View |
Page 19709 of 20943, showing 5 records out of 104715 total, starting on record 98541, ending on 98545