CVE List

Id CVE No. Status Description Phase Votes Comments Actions
95988  CVE-2016-9168  Candidate  A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking.  Assigned (20161103)  None (candidate not yet proposed)    View
30708  CVE-2008-0591  Candidate  Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by using a timer to change the window focus, aka the "dialog refocus bug" or "ffclick2".  Assigned (20080205)  None (candidate not yet proposed)    View
96244  CVE-2016-9424  Candidate  An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m doesn"t properly validate the value of tag attribute, which allows remote attackers to cause a denial of service (heap buffer overflow crash) and possibly execute arbitrary code via a crafted HTML page.  Assigned (20161118)  None (candidate not yet proposed)    View
30964  CVE-2008-0847  Candidate  SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary SQL commands via the articleid parameter.  Assigned (20080220)  None (candidate not yet proposed)    View
96500  CVE-2016-9680  Candidate  Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive information from kernel memory via unspecified vectors.  Assigned (20161130)  None (candidate not yet proposed)    View

Page 20025 of 20943, showing 5 records out of 104715 total, starting on record 100121, ending on 100125

Actions