CVE List

Id CVE No. Status Description Phase Votes Comments Actions
89846  CVE-2016-3027  Candidate  IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume all available memory resources.  Assigned (20160309)  None (candidate not yet proposed)    View
24566  CVE-2007-1209  Candidate  Use-after-free vulnerability in the Client/Server Run-time Subsystem (CSRSS) in Microsoft Windows Vista does not properly handle connection resources when starting and stopping processes, which allows local users to gain privileges by opening and closing multiple ApiPort connections, which leaves a "dangling pointer" to a process data structure.  Assigned (20070302)  None (candidate not yet proposed)    View
90102  CVE-2016-3283  Candidate  Microsoft Word Viewer allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Memory Corruption Vulnerability."  Assigned (20160315)  None (candidate not yet proposed)    View
24822  CVE-2007-1465  Candidate  Stack-based buffer overflow in dproxy.c for dproxy 0.1 through 0.5 allows remote attackers to execute arbitrary code via a long DNS query packet to UDP port 53.  Assigned (20070316)  None (candidate not yet proposed)    View
90358  CVE-2016-3539  Candidate  Unspecified vulnerability in the Oracle Agile PLM component in Oracle Supply Chain Products Suite 9.3.4 and 9.3.5 allows remote authenticated users to affect integrity and availability via vectors related to File Folders / Attachment, a different vulnerability than CVE-2016-3538.  Assigned (20160317)  None (candidate not yet proposed)    View

Page 20184 of 20943, showing 5 records out of 104715 total, starting on record 100916, ending on 100920

Actions