CVE List

Id CVE No. Status Description Phase Votes Comments Actions
24818  CVE-2007-1461  Candidate  The compress.bzip2:// URL wrapper provided by the bz2 extension in PHP before 4.4.7, and 5.x before 5.2.2, does not implement safemode or open_basedir checks, which allows remote attackers to read bzip2 archives located outside of the intended directories.  Assigned (20070314)  None (candidate not yet proposed)    View
90354  CVE-2016-3535  Candidate  Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 12.1.3 allows remote attackers to affect confidentiality and integrity via vectors related to Remote Launch. NOTE: the previous information is from the July 2016 CPU. Oracle has not commented on third-party claims that this issue is a cross-site scripting (XSS) vulnerability, which allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20160317)  None (candidate not yet proposed)    View
25074  CVE-2007-1717  Candidate  The mail function in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 truncates e-mail messages at the first ASCIIZ ("") byte, which might allow context-dependent attackers to prevent intended information from being delivered in e-mail messages. NOTE: this issue might be security-relevant in cases when the trailing contents of e-mail messages are important, such as logging information or if the message is expected to be well-formed.  Assigned (20070327)  None (candidate not yet proposed)    View
90610  CVE-2016-3791  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160330)  None (candidate not yet proposed)    View
25330  CVE-2007-1973  Candidate  Race condition in the Virtual DOS Machine (VDM) in the Windows Kernel in Microsoft Windows NT 4.0 allows local users to modify memory and gain privileges via the temporary DevicePhysicalMemory section handle, a related issue to CVE-2007-1206.  Assigned (20070411)  None (candidate not yet proposed)    View

Page 19862 of 20943, showing 5 records out of 104715 total, starting on record 99306, ending on 99310

Actions