CVE List

Id CVE No. Status Description Phase Votes Comments Actions
92663  CVE-2016-5843  Candidate  Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted search parameters.  Assigned (20160623)  None (candidate not yet proposed)    View
27383  CVE-2007-4026  Candidate  epesi framework before 0.8.6 does not properly verify file extensions, which allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving the gallery images upload feature. NOTE: some of these details are obtained from third party information.  Assigned (20070726)  None (candidate not yet proposed)    View
92919  CVE-2016-6099  Candidate  IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system.  Assigned (20160629)  None (candidate not yet proposed)    View
27639  CVE-2007-4282  Candidate  The "Extended properties for entries" (entryproperties) plugin in serendipity_event_entryproperties.php in Serendipity 1.1.3 allows remote authenticated users to bypass password protection and "deliver custom entryproperties settings to the Serendipity Frontend" via a certain request that modifies the password being checked.  Assigned (20070809)  None (candidate not yet proposed)    View
93175  CVE-2016-6355  Candidate  Memory leak in Cisco IOS XR 5.1.x through 5.1.3, 5.2.x through 5.2.5, and 5.3.x through 5.3.2 on ASR 9001 devices allows remote attackers to cause a denial of service (control-plane protocol outage) via crafted fragmented packets, aka Bug ID CSCux26791.  Assigned (20160726)  None (candidate not yet proposed)    View

Page 20268 of 20943, showing 5 records out of 104715 total, starting on record 101336, ending on 101340

Actions