CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25591  CVE-2007-2234  Candidate  include/common.php in PunBB 1.2.14 and earlier does not properly handle a disabled ini_get function when checking the register_globals setting, which allows remote attackers to register global parameters, as demonstrated by an SQL injection attack on the search_id parameter to search.php.  Assigned (20070425)  None (candidate not yet proposed)    View
91127  CVE-2016-4308  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160427)  None (candidate not yet proposed)    View
25847  CVE-2007-2490  Candidate  Unspecified vulnerability in LiveData Server before 5.00.62 allows remote attackers to cause a denial of service (exit) via crafted Connection-Oriented Transport Protocol (COTP) packets.  Assigned (20070503)  None (candidate not yet proposed)    View
91383  CVE-2016-4564  Candidate  The DrawImage function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 makes an incorrect function call in attempting to locate the next token, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.  Assigned (20160506)  None (candidate not yet proposed)    View
26103  CVE-2007-2746  Candidate  The viewList function in lib/WebGUI/Asset/Wobject/DataForm.pm in Plain Black WebGUI before 7.3.14 does not properly use data structures containing privilege information, which allows remote authenticated users to obtain sensitive information or possibly have other unspecified impact.  Assigned (20070517)  None (candidate not yet proposed)    View

Page 20260 of 20943, showing 5 records out of 104715 total, starting on record 101296, ending on 101300

Actions