CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
92663 | CVE-2016-5843 | Candidate | Multiple SQL injection vulnerabilities in the FAQ package 2.x before 2.3.6, 4.x before 4.0.5, and 5.x before 5.0.5 in Open Ticket Request System (OTRS) allow remote attackers to execute arbitrary SQL commands via crafted search parameters. | Assigned (20160623) | None (candidate not yet proposed) | View | |
27383 | CVE-2007-4026 | Candidate | epesi framework before 0.8.6 does not properly verify file extensions, which allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors involving the gallery images upload feature. NOTE: some of these details are obtained from third party information. | Assigned (20070726) | None (candidate not yet proposed) | View | |
92919 | CVE-2016-6099 | Candidate | IBM Tivoli Key Lifecycle Manager 2.5 and 2.6 discloses sensitive information to unauthorized users. The information can be used to mount further attacks on the system. | Assigned (20160629) | None (candidate not yet proposed) | View | |
27639 | CVE-2007-4282 | Candidate | The "Extended properties for entries" (entryproperties) plugin in serendipity_event_entryproperties.php in Serendipity 1.1.3 allows remote authenticated users to bypass password protection and "deliver custom entryproperties settings to the Serendipity Frontend" via a certain request that modifies the password being checked. | Assigned (20070809) | None (candidate not yet proposed) | View | |
93175 | CVE-2016-6355 | Candidate | Memory leak in Cisco IOS XR 5.1.x through 5.1.3, 5.2.x through 5.2.5, and 5.3.x through 5.3.2 on ASR 9001 devices allows remote attackers to cause a denial of service (control-plane protocol outage) via crafted fragmented packets, aka Bug ID CSCux26791. | Assigned (20160726) | None (candidate not yet proposed) | View |
Page 20268 of 20943, showing 5 records out of 104715 total, starting on record 101336, ending on 101340