CVE List

Id CVE No. Status Description Phase Votes Comments Actions
38645  CVE-2009-1210  Candidate  Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name. NOTE: some of these details are obtained from third party information.  Assigned (20090331)  None (candidate not yet proposed)    View
104181  CVE-2017-7361  Candidate  Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.  Assigned (20170330)  None (candidate not yet proposed)    View
38901  CVE-2009-1466  Candidate  Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in cleartext in aas.ini, which allows local users to obtain sensitive information by reading this file.  Assigned (20090428)  None (candidate not yet proposed)    View
104437  CVE-2017-7617  Candidate  Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in chan_sip, the CDR dialplan function, and the AMI Monitor action.  Assigned (20170410)  None (candidate not yet proposed)    View
39157  CVE-2009-1722  Candidate  Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors.  Assigned (20090520)  None (candidate not yet proposed)    View

Page 20127 of 20943, showing 5 records out of 104715 total, starting on record 100631, ending on 100635

Actions