CVE List

Id CVE No. Status Description Phase Votes Comments Actions
95990  CVE-2016-9170  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161103)  None (candidate not yet proposed)    View
30710  CVE-2008-0593  Candidate  Gecko-based browsers, including Mozilla Firefox before 2.0.0.12 and SeaMonkey before 1.1.8, modify the .href property of stylesheet DOM nodes to the final URI of a 302 redirect, which might allow remote attackers to bypass the Same Origin Policy and read sensitive information from the original URL, such as with Single-Signon systems.  Assigned (20080205)  None (candidate not yet proposed)    View
96246  CVE-2016-9426  Candidate  An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Integer overflow vulnerability in the renderTable function in w3m allows remote attackers to cause a denial of service (OOM) and possibly execute arbitrary code due to bdwgc"s bug (CVE-2016-9427) via a crafted HTML page.  Assigned (20161118)  None (candidate not yet proposed)    View
30966  CVE-2008-0849  Candidate  SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the cat parameter in a selectcat function, a different vector than CVE-2008-0652.  Assigned (20080220)  None (candidate not yet proposed)    View
96502  CVE-2016-9682  Candidate  The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to two Remote Command Injection vulnerabilities in its web administrative interface. These vulnerabilities occur in the diagnostics CGI (/cgi-bin/diagnostics) component responsible for emailing out information about the state of the system. The application doesn"t properly escape the information passed in the "tsrDeleteRestartedFile" or "currentTSREmailTo" variables before making a call to system(), allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.  Assigned (20161130)  None (candidate not yet proposed)    View

Page 20188 of 20943, showing 5 records out of 104715 total, starting on record 100936, ending on 100940

Actions