CVE List

Id CVE No. Status Description Phase Votes Comments Actions
92150  CVE-2016-5331  Candidate  CRLF injection vulnerability in VMware vCenter Server 6.0 before U2 and ESXi 6.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.  Assigned (20160607)  None (candidate not yet proposed)    View
26870  CVE-2007-3513  Candidate  The lcd_write function in drivers/usb/misc/usblcd.c in the Linux kernel before 2.6.22-rc7 does not limit the amount of memory used by a caller, which allows local users to cause a denial of service (memory consumption).  Assigned (20070702)  None (candidate not yet proposed)    View
92406  CVE-2016-5587  Candidate  Unspecified vulnerability in the Oracle Customer Interaction History component in Oracle E-Business Suite 12.1.1 through 12.1.3, 12.2.3, and 12.2.4 allows remote attackers to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2016-5591 and CVE-2016-5593.  Assigned (20160616)  None (candidate not yet proposed)    View
27126  CVE-2007-3769  Candidate  Cross-site scripting (XSS) vulnerability in the mirrored server management interface in SurgeFTP 2.3a1 allows user-assisted, remote FTP servers to inject arbitrary web script or HTML via a malformed response without a status code, which is reflected to the user in the resulting error message. NOTE: this can be leveraged for root access via a sequence of steps involving web script that creates a new FTP user account.  Assigned (20070715)  None (candidate not yet proposed)    View
92662  CVE-2016-5842  Candidate  MagickCore/property.c in ImageMagick before 7.0.2-1 allows remote attackers to obtain sensitive memory information via vectors involving the q variable, which triggers an out-of-bounds read.  Assigned (20160623)  None (candidate not yet proposed)    View

Page 20182 of 20943, showing 5 records out of 104715 total, starting on record 100906, ending on 100910

Actions