CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25844  CVE-2007-2487  Candidate  Stack-based buffer overflow in AtomixMP3 allows remote attackers to execute arbitrary code via a long filename in an MP3 file, a different vector than CVE-2006-6287.  Assigned (20070503)  None (candidate not yet proposed)    View
91380  CVE-2016-4561  Candidate  Cross-site scripting (XSS) vulnerability in the cgierror function in CGI.pm in ikiwiki before 3.20160506 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving an error message.  Assigned (20160506)  None (candidate not yet proposed)    View
26100  CVE-2007-2743  Candidate  PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitrary PHP code via a URL in the sys[path_addon] parameter.  Assigned (20070517)  None (candidate not yet proposed)    View
91636  CVE-2016-4817  Candidate  lib/http2/connection.c in H2O before 1.7.3 and 2.x before 2.0.0-beta5 mishandles HTTP/2 disconnection, which allows remote attackers to cause a denial of service (use-after-free and application crash) or possibly execute arbitrary code via a crafted packet.  Assigned (20160517)  None (candidate not yet proposed)    View
26356  CVE-2007-2999  Candidate  Microsoft Windows Server 2003, when time restrictions are in effect for user accounts, generates different error messages for failed login attempts with a valid user name than for those with an invalid user name, which allows context-dependent attackers to determine valid Active Directory account names.  Assigned (20070604)  None (candidate not yet proposed)    View

Page 20027 of 20943, showing 5 records out of 104715 total, starting on record 100131, ending on 100135

Actions