CVE List

Id CVE No. Status Description Phase Votes Comments Actions
95732  CVE-2016-8912  Candidate  IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be read by an authenticated user.  Assigned (20161025)  None (candidate not yet proposed)    View
30452  CVE-2008-0335  Candidate  Cross-site scripting (XSS) vulnerability in BugTracker.NET before 2.7.2 allows remote attackers to inject arbitrary web script or HTML via an arbitrary custom text field.  Assigned (20080117)  None (candidate not yet proposed)    View
95988  CVE-2016-9168  Candidate  A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking.  Assigned (20161103)  None (candidate not yet proposed)    View
30708  CVE-2008-0591  Candidate  Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by using a timer to change the window focus, aka the "dialog refocus bug" or "ffclick2".  Assigned (20080205)  None (candidate not yet proposed)    View
96244  CVE-2016-9424  Candidate  An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m doesn"t properly validate the value of tag attribute, which allows remote attackers to cause a denial of service (heap buffer overflow crash) and possibly execute arbitrary code via a crafted HTML page.  Assigned (20161118)  None (candidate not yet proposed)    View

Page 20034 of 20943, showing 5 records out of 104715 total, starting on record 100166, ending on 100170

Actions