CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
104433 | CVE-2017-7613 | Candidate | elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file. | Assigned (20170409) | None (candidate not yet proposed) | View | |
39153 | CVE-2009-1718 | Candidate | WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to obtain sensitive information via vectors involving drag events and the dragging of content over a crafted web page. | Assigned (20090520) | None (candidate not yet proposed) | View | |
104689 | CVE-2017-7869 | Candidate | GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflow and heap-based buffer overflow related to the cdk_pkt_read function in opencdk/read-packet.c. This issue (which is a subset of the vendor"s GNUTLS-SA-2017-3 report) is fixed in 3.5.10. | Assigned (20170414) | None (candidate not yet proposed) | View | |
39409 | CVE-2009-1974 | Candidate | Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to the Servlet Container Package. | Assigned (20090608) | None (candidate not yet proposed) | View | |
39665 | CVE-2009-2230 | Candidate | SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy parameter. | Assigned (20090626) | None (candidate not yet proposed) | View |
Page 19807 of 20943, showing 5 records out of 104715 total, starting on record 99031, ending on 99035