CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104433  CVE-2017-7613  Candidate  elflint.c in elfutils 0.168 does not validate the number of sections and the number of segments, which allows remote attackers to cause a denial of service (memory consumption) via a crafted ELF file.  Assigned (20170409)  None (candidate not yet proposed)    View
39153  CVE-2009-1718  Candidate  WebKit in Apple Safari before 4.0 allows user-assisted remote attackers to obtain sensitive information via vectors involving drag events and the dragging of content over a crafted web page.  Assigned (20090520)  None (candidate not yet proposed)    View
104689  CVE-2017-7869  Candidate  GnuTLS before 2017-02-20 has an out-of-bounds write caused by an integer overflow and heap-based buffer overflow related to the cdk_pkt_read function in opencdk/read-packet.c. This issue (which is a subset of the vendor"s GNUTLS-SA-2017-3 report) is fixed in 3.5.10.  Assigned (20170414)  None (candidate not yet proposed)    View
39409  CVE-2009-1974  Candidate  Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3, 10.0 MP1, 9.2 MP3, 9.1, 9.0, 8.1 SP6, and 7.0 SP7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to the Servlet Container Package.  Assigned (20090608)  None (candidate not yet proposed)    View
39665  CVE-2009-2230  Candidate  SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authenticated users to execute arbitrary SQL commands via the birthdayprivacy parameter.  Assigned (20090626)  None (candidate not yet proposed)    View

Page 19807 of 20943, showing 5 records out of 104715 total, starting on record 99031, ending on 99035

Actions