CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25078  CVE-2007-1721  Candidate  Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) Richtxt_functions.inc.php, (2) adddocfile.php, (3) auth_check.php, (4) browse_current_category.inc.php, (5) docfile_details.php, (6) main.php, (7) mainarticle.php, (8) maindocfile.php, (9) modify.php, (10) new.php, (11) resource_details.php, or (12) smallsearch.php in lib/; or (13) mwiki/LocalSettings.php.  Assigned (20070327)  None (candidate not yet proposed)    View
90614  CVE-2016-3795  Candidate  The MediaTek power driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28085222 and MediaTek internal bug ALPS02677244.  Assigned (20160330)  None (candidate not yet proposed)    View
25334  CVE-2007-1977  Candidate  Cross-site scripting (XSS) vulnerability in index_cms.php in holaCMS 1.4.10 allows remote attackers to inject arbitrary web script or HTML via the acuparam parameter.  Assigned (20070411)  None (candidate not yet proposed)    View
90870  CVE-2016-4051  Candidate  Buffer overflow in cachemgr.cgi in Squid 2.x, 3.x before 3.5.17, and 4.x before 4.0.9 might allow remote attackers to cause a denial of service or execute arbitrary code by seeding manager reports with crafted data.  Assigned (20160420)  None (candidate not yet proposed)    View
25590  CVE-2007-2233  Candidate  cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR ( ) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.  Assigned (20070425)  None (candidate not yet proposed)    View

Page 20185 of 20943, showing 5 records out of 104715 total, starting on record 100921, ending on 100925

Actions