CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36604 | CVE-2008-6487 | Candidate | Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) admin and (2) password fields. | Assigned (20090318) | None (candidate not yet proposed) | View | |
102140 | CVE-2017-5320 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170109) | None (candidate not yet proposed) | View | |
36860 | CVE-2008-6743 | Candidate | RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php. | Assigned (20090422) | None (candidate not yet proposed) | View | |
102396 | CVE-2017-5576 | Candidate | Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted size value in a VC4_SUBMIT_CL ioctl call. | Assigned (20170124) | None (candidate not yet proposed) | View | |
37116 | CVE-2008-6999 | Candidate | phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. | Assigned (20090817) | None (candidate not yet proposed) | View |
Page 20070 of 20943, showing 5 records out of 104715 total, starting on record 100346, ending on 100350