CVE List

Id CVE No. Status Description Phase Votes Comments Actions
91639  CVE-2016-4820  Candidate  Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE ETX-R devices allows remote attackers to hijack the authentication of arbitrary users.  Assigned (20160517)  None (candidate not yet proposed)    View
26359  CVE-2007-3002  Candidate  PHP JackKnife (PHPJK) allows remote attackers to obtain sensitive information via (1) a request to index.php with an invalid value of the iParentUnq[] parameter, or a request to G_Display.php with an invalid (2) iCategoryUnq[] or (3) sSort[] array parameter, which reveals the path in various error messages.  Assigned (20070604)  None (candidate not yet proposed)    View
91895  CVE-2016-5076  Candidate  CloudView NMS before 2.10a allows remote attackers to obtain sensitive information via a direct request for admin/auto.def.  Assigned (20160526)  None (candidate not yet proposed)    View
26615  CVE-2007-3258  Candidate  calendar.php in Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via large values to the (1) year and (2) month parameters, which causes negative values to be passed to the mktime library call, and reveals the installation path in the error message.  Assigned (20070619)  None (candidate not yet proposed)    View
92151  CVE-2016-5332  Candidate  Directory traversal vulnerability in VMware vRealize Log Insight 2.x and 3.x before 3.6.0 allows remote attackers to read arbitrary files via unspecified vectors.  Assigned (20160607)  None (candidate not yet proposed)    View

Page 20261 of 20943, showing 5 records out of 104715 total, starting on record 101301, ending on 101305

Actions