CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
27126 | CVE-2007-3769 | Candidate | Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to inject arbitrary web script or HTML via a malformed response without a status code, which is reflected to the user in the resulting error message. NOTE: this can be leveraged for root access via a sequence of steps involving web script that creates a new FTP user account. | Assigned (20070715) | None (candidate not yet proposed) | View | |
92662 | CVE-2016-5842 | Candidate | MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read. | Assigned (20160623) | None (candidate not yet proposed) | View | |
27382 | CVE-2007-4025 | Candidate | Unspecified vulnerability in Sun Java System (SJS) Application Server 8.1 through 9.0 before 20070724 on Windows allows remote attackers to obtain JSP source code via unspecified vectors. | Assigned (20070726) | None (candidate not yet proposed) | View | |
92918 | CVE-2016-6098 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20160629) | None (candidate not yet proposed) | View | |
27638 | CVE-2007-4281 | Candidate | Cross-site scripting (XSS) vulnerability in KnowledgeTree Open Source 3.4 and 3.4.1 allows remote attackers to inject arbitrary web script or HTML via the login field on the login page, and other unspecified vectors. | Assigned (20070809) | None (candidate not yet proposed) | View |
Page 20174 of 20943, showing 5 records out of 104715 total, starting on record 100866, ending on 100870