CVE List

Id CVE No. Status Description Phase Votes Comments Actions
27378  CVE-2007-4021  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in login.php in Brain Book Software Secure 1.0.20070629 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user and (2) pwd parameters.  Assigned (20070726)  None (candidate not yet proposed)    View
92914  CVE-2016-6094  Candidate  IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 generates an error message that includes sensitive information about its environment, users, or associated data.  Assigned (20160629)  None (candidate not yet proposed)    View
27634  CVE-2007-4277  Candidate  The Trend Micro AntiVirus scan engine before 8.550-1001, as used in Trend Micro PC-Cillin Internet Security 2007, and Tmxpflt.sys 8.320.1004 and 8.500.0.1002, has weak permissions (Everyone:Write) for the \.Tmfilter device, which allows local users to send arbitrary content to the device via the IOCTL functionality. NOTE: this can be leveraged for privilege escalation by exploiting a buffer overflow in the handler for IOCTL 0xa0284403.  Assigned (20070809)  None (candidate not yet proposed)    View
93170  CVE-2016-6350  Candidate  OpenBSD 5.8 and 5.9 allows local users to cause a denial of service (NULL pointer dereference and panic) via a sysctl call with a path starting with 10,9.  Assigned (20160726)  None (candidate not yet proposed)    View
27890  CVE-2007-4533  Candidate  Format string vulnerability in the Say command in sv_main.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via format string specifiers in a chat message, related to a call to the BroadcastPrintf function.  Assigned (20070824)  None (candidate not yet proposed)    View

Page 19866 of 20943, showing 5 records out of 104715 total, starting on record 99326, ending on 99330

Actions