CVE List

Id CVE No. Status Description Phase Votes Comments Actions
86006  CVE-2015-8729  Candidate  The ascend_seek function in wiretap/ascendtext.c in the Ascend file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not ensure the presence of a "" character at the end of a date string, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.  Assigned (20160103)  None (candidate not yet proposed)    View
20726  CVE-2006-4622  Candidate  PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.  Assigned (20060906)  None (candidate not yet proposed)    View
86262  CVE-2015-8985  Candidate  The pop_fail_stack function in the GNU C Library (aka glibc or libc6) allows context-dependent attackers to cause a denial of service (assertion failure and application crash) via vectors related to extended regular expression processing.  Assigned (20170214)  None (candidate not yet proposed)    View
20982  CVE-2006-4878  Candidate  Directory traversal vulnerability in footer.php in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to read and include arbitrary local files via a .. (dot dot) sequence in the template parameter. NOTE: this was later reported to affect 1.0.1, and demonstrated for code execution by uploading and accessing an avatar file.  Assigned (20060919)  None (candidate not yet proposed)    View
86518  CVE-2016-0222  Candidate  IBM Maximo Asset Management 7.6 before 7.6.0.3 IFIX001 allows remote authenticated users to bypass intended access restrictions and read arbitrary purchase-order work logs via unspecified vectors.  Assigned (20151208)  None (candidate not yet proposed)    View

Page 20178 of 20943, showing 5 records out of 104715 total, starting on record 100886, ending on 100890

Actions