CVE List

Id CVE No. Status Description Phase Votes Comments Actions
27379  CVE-2007-4022  Candidate  Cross-site scripting (XSS) vulnerability in frontend/x/htaccess/changepro.html in cPanel 10.9.1 allows remote attackers to inject arbitrary web script or HTML via the resname parameter.  Assigned (20070726)  None (candidate not yet proposed)    View
92915  CVE-2016-6095  Candidate  IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.  Assigned (20160629)  None (candidate not yet proposed)    View
27635  CVE-2007-4278  Candidate  Stack-based buffer overflow in the giomgr process in ESRI ArcSDE service 9.2, as used with ArcGIS, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a large number that requires more than 8 bytes to represent in ASCII, which triggers the overflow in an sprintf function call.  Assigned (20070809)  None (candidate not yet proposed)    View
93171  CVE-2016-6351  Candidate  The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execute arbitrary code on the QEMU host via vectors involving DMA read into ESP command buffer.  Assigned (20160726)  None (candidate not yet proposed)    View
27891  CVE-2007-4534  Candidate  Buffer overflow in the VThinker::BroadcastPrintf function in p_thinker.cpp in Vavoom 1.24 and earlier allows remote attackers to execute arbitrary code via (1) a long string in a chat message and possibly (2) a long name field.  Assigned (20070824)  None (candidate not yet proposed)    View

Page 19943 of 20943, showing 5 records out of 104715 total, starting on record 99711, ending on 99715

Actions