CVE List

Id CVE No. Status Description Phase Votes Comments Actions
89330  CVE-2016-2511  Candidate  Cross-site scripting (XSS) vulnerability in WebSVN 2.3.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the path parameter to log.php.  Assigned (20160219)  None (candidate not yet proposed)    View
24050  CVE-2007-0693  Candidate  SQL injection vulnerability in news.php in DGNews 2.1 allows remote attackers to execute arbitrary SQL commands via the catid parameter in a newslist action. NOTE: this issue can produce resultant cross-site scripting (XSS).  Assigned (20070203)  None (candidate not yet proposed)    View
89586  CVE-2016-2767  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160226)  None (candidate not yet proposed)    View
24306  CVE-2007-0949  Candidate  Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers to execute arbitrary code via a M3U playlist file that contains a long file name. NOTE: it was later reported that 1.20 and 1.30 are also affected.  Assigned (20070214)  None (candidate not yet proposed)    View
89842  CVE-2016-3023  Candidate  IBM Security Access Manager for Web could allow an unauthenticated user to gain access to sensitive information by entering invalid file names.  Assigned (20160309)  None (candidate not yet proposed)    View

Page 19865 of 20943, showing 5 records out of 104715 total, starting on record 99321, ending on 99325

Actions