CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
88062 | CVE-2016-1243 | Candidate | Stack-based buffer overflow in the extractTree function in unADF allows remote attackers to execute arbitrary code via a long pathname. | Assigned (20151227) | None (candidate not yet proposed) | View | |
22782 | CVE-2006-6678 | Candidate | The edit_textarea function in form-file.c in Netrik 1.15.4 and earlier does not properly verify temporary filenames when editing textarea fields, which allows attackers to execute arbitrary commands via shell metacharacters in the filename. | Assigned (20061220) | None (candidate not yet proposed) | View | |
88318 | CVE-2016-1499 | Candidate | ownCloud Server before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2 allow remote authenticated users to obtain sensitive information from a directory listing and possibly cause a denial of service (CPU consumption) via the force parameter to index.php/apps/files/ajax/scan.php. | Assigned (20160106) | None (candidate not yet proposed) | View | |
23038 | CVE-2006-6934 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Portix-PHP 0.4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) titre or (2) auteur field in a forum post. | Assigned (20070116) | None (candidate not yet proposed) | View | |
88574 | CVE-2016-1755 | Candidate | The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-1754. | Assigned (20160113) | None (candidate not yet proposed) | View |
Page 20207 of 20943, showing 5 records out of 104715 total, starting on record 101031, ending on 101035