CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
38645 | CVE-2009-1210 | Candidate | Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attackers to execute arbitrary code via a PN-DCP packet with format string specifiers in the station name. NOTE: some of these details are obtained from third party information. | Assigned (20090331) | None (candidate not yet proposed) | View | |
104181 | CVE-2017-7361 | Candidate | Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack. | Assigned (20170330) | None (candidate not yet proposed) | View | |
38901 | CVE-2009-1466 | Candidate | Application Access Server (A-A-S) 2.0.48 stores (1) passwords and (2) the port keyword in cleartext in aas.ini, which allows local users to obtain sensitive information by reading this file. | Assigned (20090428) | None (candidate not yet proposed) | View | |
104437 | CVE-2017-7617 | Candidate | Remote code execution can occur in Asterisk Open Source 13.x before 13.14.1 and 14.x before 14.3.1 and Certified Asterisk 13.13 before 13.13-cert3 because of a buffer overflow in a CDR user field, related to X-ClientCode in chan_sip, the CDR dialplan function, and the AMI Monitor action. | Assigned (20170410) | None (candidate not yet proposed) | View | |
39157 | CVE-2009-1722 | Candidate | Heap-based buffer overflow in the compression implementation in OpenEXR 1.2.2 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors. | Assigned (20090520) | None (candidate not yet proposed) | View |
Page 20127 of 20943, showing 5 records out of 104715 total, starting on record 100631, ending on 100635