CVE List

Id CVE No. Status Description Phase Votes Comments Actions
27127  CVE-2007-3770  Candidate  The terminal_helper_execute function in terminal/terminal.c in Xfce Terminal 0.2.6 allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters in a crafted link, as demonstrated using the "Open Link" functionality.  Assigned (20070715)  None (candidate not yet proposed)    View
92663  CVE-2016-5843  Candidate  Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted search parameters.  Assigned (20160623)  None (candidate not yet proposed)    View
27383  CVE-2007-4026  Candidate  epesi framework before 0.8.6 does not properly verify file extensions, which allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving the gallery images upload feature. NOTE: some of these details are obtained from third party information.  Assigned (20070726)  None (candidate not yet proposed)    View
92919  CVE-2016-6099  Candidate  IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system.  Assigned (20160629)  None (candidate not yet proposed)    View
27639  CVE-2007-4282  Candidate  The "Extended properties for entries" (entryproperties) plugin in serendipity_event_entryproperties.php in Serendipity 1.1.3 allows remote authenticated users to bypass password protection and "deliver custom entryproperties settings to the Serendipity Frontend" via a certain request that modifies the password being checked.  Assigned (20070809)  None (candidate not yet proposed)    View

Page 20251 of 20943, showing 5 records out of 104715 total, starting on record 101251, ending on 101255

Actions