CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
95732 | CVE-2016-8912 | Candidate | IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be read by an authenticated user. | Assigned (20161025) | None (candidate not yet proposed) | View | |
30452 | CVE-2008-0335 | Candidate | Cross-site scripting (XSS) vulnerability in BugTracker.NET before 2.7.2 allows remote attackers to inject arbitrary web script or HTML via an arbitrary custom text field. | Assigned (20080117) | None (candidate not yet proposed) | View | |
95988 | CVE-2016-9168 | Candidate | A missing X-Frame-Options header in the NDS Utility Monitor in NDSD in Novell eDirectory before 9.0.2 could be used by remote attackers for clickjacking. | Assigned (20161103) | None (candidate not yet proposed) | View | |
30708 | CVE-2008-0591 | Candidate | Mozilla Firefox before 2.0.0.12 and Thunderbird before 2.0.0.12 does not properly manage a delay timer used in confirmation dialogs, which might allow remote attackers to trick users into confirming an unsafe action, such as remote file execution, by using a timer to change the window focus, aka the "dialog refocus bug" or "ffclick2". | Assigned (20080205) | None (candidate not yet proposed) | View | |
96244 | CVE-2016-9424 | Candidate | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m doesn"t properly validate the value of tag attribute, which allows remote attackers to cause a denial of service (heap buffer overflow crash) and possibly execute arbitrary code via a crafted HTML page. | Assigned (20161118) | None (candidate not yet proposed) | View |
Page 20034 of 20943, showing 5 records out of 104715 total, starting on record 100166, ending on 100170