CVE List

Id CVE No. Status Description Phase Votes Comments Actions
30455  CVE-2008-0338  Candidate  Directory traversal vulnerability in the mwGetLocalFileName function in http.c in MiniWeb HTTP Server 0.8.19 allows remote attackers to read arbitrary files and list arbitrary directories via a (1) .%2e (partially encoded dot dot) or (2) %2e%2e (encoded dot dot) in the URI.  Assigned (20080117)  None (candidate not yet proposed)    View
95991  CVE-2016-9171  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161103)  None (candidate not yet proposed)    View
30711  CVE-2008-0594  Candidate  Mozilla Firefox before 2.0.0.12 does not always display a web forgery warning dialog if the entire contents of a web page are in a DIV tag that uses absolute positioning, which makes it easier for remote attackers to conduct phishing attacks.  Assigned (20080205)  None (candidate not yet proposed)    View
96247  CVE-2016-9427  Candidate  Integer overflow vulnerability in bdwgc before 2016-09-27 allows attackers to cause client of bdwgc denial of service (heap buffer overflow crash) and possibly execute arbitrary code via huge allocation.  Assigned (20161118)  None (candidate not yet proposed)    View
30967  CVE-2008-0850  Candidate  Multiple SQL injection vulnerabilities in Dokeos 1.8.4 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to whoisonline.php, (2) tracking_list_coaches_column parameter to main/mySpace/index.php, (3) tutor_name parameter to main/create_course/add_course.php, the (4) Referer HTTP header to index.php, and the (5) X-Fowarded-For HTTP header to main/admin/class_list.php.  Assigned (20080220)  None (candidate not yet proposed)    View

Page 20273 of 20943, showing 5 records out of 104715 total, starting on record 101361, ending on 101365

Actions