CVE List

Id CVE No. Status Description Phase Votes Comments Actions
85750  CVE-2015-8473  Candidate  The Issues API in Redmine before 2.6.8, 3.0.x before 3.0.6, and 3.1.x before 3.1.2 allows remote authenticated users to obtain sensitive information in changeset messages by leveraging permission to read issues with related changesets from other projects.  Assigned (20151204)  None (candidate not yet proposed)    View
20470  CVE-2006-4366  Candidate  PHP remote file inclusion vulnerability in index.php in RedBLoG 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.  Assigned (20060825)  None (candidate not yet proposed)    View
86006  CVE-2015-8729  Candidate  The ascend_seek function in wiretap/ascendtext.c in the Ascend file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not ensure the presence of a "" character at the end of a date string, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.  Assigned (20160103)  None (candidate not yet proposed)    View
20726  CVE-2006-4622  Candidate  PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.  Assigned (20060906)  None (candidate not yet proposed)    View
86262  CVE-2015-8985  Candidate  The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service (assertion failure and application crash) via vectors related to extended regular expression processing.  Assigned (20170214)  None (candidate not yet proposed)    View

Page 20172 of 20943, showing 5 records out of 104715 total, starting on record 100856, ending on 100860

Actions