CVE List

Id CVE No. Status Description Phase Votes Comments Actions
37619  CVE-2009-0184  Candidate  Multiple buffer overflows in the torrent parsing implementation in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allow remote attackers to execute arbitrary code via (1) a long file name within a torrent file, (2) a long tracker URL in a torrent file, or (3) a long comment in a torrent file.  Assigned (20090120)  None (candidate not yet proposed)    View
103155  CVE-2017-6335  Candidate  The QuantumTransferMode function in coders/tiff.c in GraphicsMagick 1.3.25 and earlier allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a small samples per pixel value in a CMYKA TIFF file.  Assigned (20170226)  None (candidate not yet proposed)    View
37875  CVE-2009-0440  Candidate  IBM WebSphere Partner Gateway (WPG) 6.0.0 through 6.0.0.7 does not properly handle failures of signature verification, which might allow remote authenticated users to submit a crafted RosettaNet (aka RNIF) document to a backend application, related to (1) "altered service content" and (2) "digital signature foot-print."  Assigned (20090205)  None (candidate not yet proposed)    View
103411  CVE-2017-6591  Candidate  There is a cross-site scripting vulnerability in django-epiceditor 0.2.3 via crafted content in a form field.  Assigned (20170309)  None (candidate not yet proposed)    View
38131  CVE-2009-0696  Candidate  The dns_db_findrdataset function in db.c in named in ISC BIND 9.4 before 9.4.3-P3, 9.5 before 9.5.1-P3, and 9.6 before 9.6.1-P1, when configured as a master server, allows remote attackers to cause a denial of service (assertion failure and daemon exit) via an ANY record in the prerequisite section of a crafted dynamic update message, as exploited in the wild in July 2009.  Assigned (20090222)  None (candidate not yet proposed)    View

Page 19959 of 20943, showing 5 records out of 104715 total, starting on record 99791, ending on 99795

Actions