CVE List

Id CVE No. Status Description Phase Votes Comments Actions
90614  CVE-2016-3795  Candidate  The MediaTek power driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28085222 and MediaTek internal bug ALPS02677244.  Assigned (20160330)  None (candidate not yet proposed)    View
25334  CVE-2007-1977  Candidate  Cross-site scripting (XSS) vulnerability in index_cms.php in holaCMS 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter.  Assigned (20070411)  None (candidate not yet proposed)    View
90870  CVE-2016-4051  Candidate  Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.  Assigned (20160420)  None (candidate not yet proposed)    View
25590  CVE-2007-2233  Candidate  cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR ( ) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.  Assigned (20070425)  None (candidate not yet proposed)    View
91126  CVE-2016-4307  Candidate  A denial of service vulnerability exists in the IOCTL handling functionality of Kaspersky Internet Security KL1 driver. A specially crafted IOCTL signal can cause an access violation in KL1 kernel driver resulting in local system denial of service. An attacker can run a program from user-mode to trigger this vulnerability.  Assigned (20160427)  None (candidate not yet proposed)    View

Page 20171 of 20943, showing 5 records out of 104715 total, starting on record 100851, ending on 100855

Actions