CVE List

Id CVE No. Status Description Phase Votes Comments Actions
30204  CVE-2008-0087  Candidate  The DNS client in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, and Vista uses predictable DNS transaction IDs, which allows remote attackers to spoof DNS responses.  Assigned (20080103)  None (candidate not yet proposed)    View
95740  CVE-2016-8920  Candidate  IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.  Assigned (20161025)  None (candidate not yet proposed)    View
30460  CVE-2008-0343  Candidate  Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 has unknown impact and remote attack vectors, aka DB06.  Assigned (20080117)  None (candidate not yet proposed)    View
95996  CVE-2016-9176  Candidate  Stack buffer overflow in the send.exe and receive.exe components of Micro Focus Rumba 9.4 and earlier could be used by local attackers or attackers able to inject arguments to these binaries to execute code.  Assigned (20161103)  None (candidate not yet proposed)    View
30716  CVE-2008-0599  Candidate  The init_request_info function in sapi/cgi/cgi_main.c in PHP before 5.2.6 does not properly consider operator precedence when calculating the length of PATH_TRANSLATED, which might allow remote attackers to execute arbitrary code via a crafted URI.  Assigned (20080205)  None (candidate not yet proposed)    View

Page 20060 of 20943, showing 5 records out of 104715 total, starting on record 100296, ending on 100300

Actions