CVE List

Id CVE No. Status Description Phase Votes Comments Actions
26111  CVE-2007-2754  Candidate  Integer signedness error in truetype/ttgload.c in Freetype 2.3.4 and earlier might allow remote attackers to execute arbitrary code via a crafted TTF image with a negative n_points value, which leads to an integer overflow and heap-based buffer overflow.  Assigned (20070517)  None (candidate not yet proposed)    View
91647  CVE-2016-4828  Candidate  The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress mishandles sessions, which allows remote attackers to obtain access by leveraging knowledge of the e-mail address associated with an account.  Assigned (20160517)  None (candidate not yet proposed)    View
26367  CVE-2007-3010  Candidate  masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the user parameter during a ping action.  Assigned (20070604)  None (candidate not yet proposed)    View
91903  CVE-2016-5084  Candidate  Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive information by sniffing the network.  Assigned (20160526)  None (candidate not yet proposed)    View
26623  CVE-2007-3266  Candidate  Directory traversal vulnerability in webif.cgi in ifnet WEBIF allows remote attackers to include and execute arbitrary local files a .. (dot dot) in the outconfig parameter.  Assigned (20070619)  None (candidate not yet proposed)    View

Page 20292 of 20943, showing 5 records out of 104715 total, starting on record 101456, ending on 101460

Actions