CVE List

Id CVE No. Status Description Phase Votes Comments Actions
38899  CVE-2009-1464  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in index.aas in Application Access Server (A-A-S) 2.0.48 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrary programs via a command job, (2) stop services via a setservice job, or (3) terminate processes via a killprocess job.  Assigned (20090428)  None (candidate not yet proposed)    View
104435  CVE-2017-7615  Candidate  MantisBT through 2.3.0 allows arbitrary password reset and unauthenticated admin access via an empty confirm_hash value to verify.php.  Assigned (20170409)  None (candidate not yet proposed)    View
39155  CVE-2009-1720  Candidate  Multiple integer overflows in OpenEXR 1.2.2 and 1.6.1 allow context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors that trigger heap-based buffer overflows, related to (1) the Imf::PreviewImage::PreviewImage function and (2) compressor constructors. NOTE: some of these details are obtained from third party information.  Assigned (20090520)  None (candidate not yet proposed)    View
104691  CVE-2017-7871  Candidate  trollepierre/tdm before 2017-04-13 is vulnerable to a reflected XSS in tdm-master/webhook.php (challenge parameter).  Assigned (20170414)  None (candidate not yet proposed)    View
39411  CVE-2009-1976  Candidate  Unspecified vulnerability in the HTTP Server component in Oracle Application Server 10.1.2.3 allows remote attackers to affect integrity via unknown vectors.  Assigned (20090608)  None (candidate not yet proposed)    View

Page 19961 of 20943, showing 5 records out of 104715 total, starting on record 99801, ending on 99805

Actions