CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
37365 | CVE-2008-7248 | Candidate | Ruby on Rails 2.1 before 2.1.3 and 2.2.x before 2.2.2 does not verify tokens for requests with certain content types, which allows remote attackers to bypass cross-site request forgery (CSRF) protection for requests to applications that rely on this protection, as demonstrated using text/plain. | Assigned (20091211) | None (candidate not yet proposed) | View | |
102901 | CVE-2017-6081 | Candidate | A CSRF issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. To exploit the vulnerability, an attacker can send cross-domain requests directly to the REST API for users with a valid session cookie. | Assigned (20170218) | None (candidate not yet proposed) | View | |
37621 | CVE-2009-0186 | Candidate | Integer overflow in libsndfile 1.0.18, as used in Winamp and other products, allows context-dependent attackers to execute arbitrary code via crafted description chunks in a CAF audio file, leading to a heap-based buffer overflow. | Assigned (20090120) | None (candidate not yet proposed) | View | |
103157 | CVE-2017-6337 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170226) | None (candidate not yet proposed) | View | |
37877 | CVE-2009-0442 | Candidate | Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the l parameter. | Assigned (20090205) | None (candidate not yet proposed) | View |
Page 20125 of 20943, showing 5 records out of 104715 total, starting on record 100621, ending on 100625