CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23551  CVE-2007-0194  Candidate  admin.php in MKPortal M1.1 RC1 allows remote attackers to obtain sensitive information via a direct request with an MK_PATH=1 query string, which reveals the path in an error message.  Assigned (20070110)  None (candidate not yet proposed)    View
89087  CVE-2016-2268  Candidate  Dell SecureWorks app before 2.1 for iOS does not validate SSL certificates, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.  Assigned (20160208)  None (candidate not yet proposed)    View
23807  CVE-2007-0450  Candidate  Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.  Assigned (20070123)  None (candidate not yet proposed)    View
89343  CVE-2016-2524  Candidate  epan/dissectors/packet-x509af.c in the X.509AF dissector in Wireshark 2.0.x before 2.0.2 mishandles the algorithm ID, which allows remote attackers to cause a denial of service (application crash) via a crafted packet.  Assigned (20160220)  None (candidate not yet proposed)    View
24063  CVE-2007-0706  Candidate  Cross-zone scripting vulnerability in Darksky RSS bar for Internet Explorer before 1.29, RSS bar for Sleipnir before 1.29, and RSS bar for unDonut before 1.29 allows remote attackers to bypass Web content zone restrictions via certain script contained in RSS data. NOTE: some of these details are obtained from third party information.  Assigned (20070203)  None (candidate not yet proposed)    View

Page 20288 of 20943, showing 5 records out of 104715 total, starting on record 101436, ending on 101440

Actions