85494 |
CVE-2015-8217 |
Candidate |
The ff_hevc_parse_sps function in libavcodec/hevc_ps.c in FFmpeg before 2.8.2 does not validate the Chroma Format Indicator, which allows remote attackers to cause a denial of service (out-of-bounds array access) or possibly have unspecified other impact via crafted High Efficiency Video Coding (HEVC) data. |
Assigned (20151116) |
None (candidate not yet proposed) |
|
View
|
20214 |
CVE-2006-4110 |
Candidate |
Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems. |
Assigned (20060814) |
None (candidate not yet proposed) |
|
View
|
85750 |
CVE-2015-8473 |
Candidate |
The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects. |
Assigned (20151204) |
None (candidate not yet proposed) |
|
View
|
20470 |
CVE-2006-4366 |
Candidate |
PHP remote file inclusion vulnerability in index.php in RedBLoG 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. |
Assigned (20060825) |
None (candidate not yet proposed) |
|
View
|
86006 |
CVE-2015-8729 |
Candidate |
The ascend_seek function in wiretap/ascendtext.c in the Ascend file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not ensure the presence of a " |