CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
27124 | CVE-2007-3767 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20070713) | None (candidate not yet proposed) | View | |
92660 | CVE-2016-5840 | Candidate | hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote administrators to execute arbitrary code via shell metacharacters in the filename parameter of the Content-Disposition header. | Assigned (20160623) | None (candidate not yet proposed) | View | |
27380 | CVE-2007-4023 | Candidate | Cross-site scripting (XSS) vulnerability in the login CGI program in Aruba Mobility Controller 2.5.4.18 and earlier, and 2.4.8.6-FIPS and earlier FIPS versions, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20070726) | None (candidate not yet proposed) | View | |
92916 | CVE-2016-6096 | Candidate | IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | Assigned (20160629) | None (candidate not yet proposed) | View | |
27636 | CVE-2007-4279 | Candidate | PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_root parameter. | Assigned (20070809) | None (candidate not yet proposed) | View |
Page 20029 of 20943, showing 5 records out of 104715 total, starting on record 100141, ending on 100145