CVE List

Id CVE No. Status Description Phase Votes Comments Actions
91383  CVE-2016-4564  Candidate  The DrawImage function in MagickCore/draw.c in ImageMagick before 6.9.4-0 and 7.x before 7.0.1-2 makes an incorrect function call in attempting to locate the next token, which allows remote attackers to cause a denial of service (buffer overflow and application crash) or possibly have unspecified other impact via a crafted file.  Assigned (20160506)  None (candidate not yet proposed)    View
26103  CVE-2007-2746  Candidate  The viewList function in lib/WebGUI/Asset/Wobject/DataForm.pm in Plain Black WebGUI before 7.3.14 does not properly use data structures containing privilege information, which allows remote authenticated users to obtain sensitive information or possibly have other unspecified impact.  Assigned (20070517)  None (candidate not yet proposed)    View
91639  CVE-2016-4820  Candidate  Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE ETX-R devices allows remote attackers to hijack the authentication of arbitrary users.  Assigned (20160517)  None (candidate not yet proposed)    View
26359  CVE-2007-3002  Candidate  PHP JackKnife (PHPJK) allows remote attackers to obtain sensitive information via (1) a request to index.php with an invalid value of the iParentUnq[] parameter, or a request to G_Display.php with an invalid (2) iCategoryUnq[] or (3) sSort[] array parameter, which reveals the path in various error messages.  Assigned (20070604)  None (candidate not yet proposed)    View
91895  CVE-2016-5076  Candidate  CloudView NMS before 2.10a allows remote attackers to obtain sensitive information via a direct request for admin/auto.def.  Assigned (20160526)  None (candidate not yet proposed)    View

Page 20266 of 20943, showing 5 records out of 104715 total, starting on record 101326, ending on 101330

Actions