CVE List

Id CVE No. Status Description Phase Votes Comments Actions
24822  CVE-2007-1465  Candidate  Stack-based buffer overflow in dproxy.c for dproxy 0.1 through 0.5 allows remote attackers to execute arbitrary code via a long DNS query packet to UDP port 53.  Assigned (20070316)  None (candidate not yet proposed)    View
90358  CVE-2016-3539  Candidate  Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect integrity and availability via vectors related to File Folders / Attachment, a different vulnerability than CVE-2016-3538.  Assigned (20160317)  None (candidate not yet proposed)    View
25078  CVE-2007-1721  Candidate  Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.  Assigned (20070327)  None (candidate not yet proposed)    View
90614  CVE-2016-3795  Candidate  The MediaTek power driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28085222 and MediaTek internal bug ALPS02677244.  Assigned (20160330)  None (candidate not yet proposed)    View
25334  CVE-2007-1977  Candidate  Cross-site scripting (XSS) vulnerability in index_cms.php in holaCMS 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter.  Assigned (20070411)  None (candidate not yet proposed)    View

Page 20179 of 20943, showing 5 records out of 104715 total, starting on record 100891, ending on 100895

Actions