CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
26111 | CVE-2007-2754 | Candidate | Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow. | Assigned (20070517) | None (candidate not yet proposed) | View | |
91647 | CVE-2016-4828 | Candidate | The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress mishandles sessions, which allows remote attackers to obtain access by leveraging knowledge of the e-mail address associated with an account. | Assigned (20160517) | None (candidate not yet proposed) | View | |
26367 | CVE-2007-3010 | Candidate | masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action. | Assigned (20070604) | None (candidate not yet proposed) | View | |
91903 | CVE-2016-5084 | Candidate | Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive information by sniffing the network. | Assigned (20160526) | None (candidate not yet proposed) | View | |
26623 | CVE-2007-3266 | Candidate | Directory traversal vulnerability in webif.cgi in ifnet WEBIF allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the outconfig parameter. | Assigned (20070619) | None (candidate not yet proposed) | View |
Page 20292 of 20943, showing 5 records out of 104715 total, starting on record 101456, ending on 101460