CVE List

Id CVE No. Status Description Phase Votes Comments Actions
92159  CVE-2016-5340  Candidate  The is_ashmem_file function in drivers/staging/android/ashmem.c in a certain Qualcomm Innovation Center (QuIC) Android patch for the Linux kernel 3.x mishandles pointer validation within the KGSL Linux Graphics Module, which allows attackers to bypass intended access restrictions by using the /ashmem string as the dentry name.  Assigned (20160609)  None (candidate not yet proposed)    View
26879  CVE-2007-3522  Candidate  Multiple PHP remote file inclusion vulnerabilities in sPHPell 1.01 allow remote attackers to execute arbitrary PHP code via a URL in the SpellIncPath parameter to (1) spellcheckpageinc.php, (2) spellchecktext.php, (3) spellcheckwindow.php, or (4) spellcheckwindowframeset.php.  Assigned (20070703)  None (candidate not yet proposed)    View
92415  CVE-2016-5596  Candidate  Unspecified vulnerability in the Oracle CRM Technical Foundation component in Oracle E-Business Suite 12.1.1 through 12.1.3 and 12.2.3 through 12.2.6 allows remote authenticated users to affect confidentiality via unknown vectors.  Assigned (20160616)  None (candidate not yet proposed)    View
27135  CVE-2007-3778  Candidate  The G/PGP (GPG) Plugin 2.0, and 2.1dev before 20060912, for Squirrelmail allows remote attackers to execute arbitrary commands via shell metacharacters in the messageSignedText parameter to the gpg_check_sign_pgp_mime function in gpg_hook_functions.php. NOTE: a parameter value can be set in the contents of an e-mail message.  Assigned (20070715)  None (candidate not yet proposed)    View
92671  CVE-2016-5851  Candidate  python-docx before 0.8.6 allows context-dependent attackers to conduct XML External Entity (XXE) attacks via a crafted document.  Assigned (20160628)  None (candidate not yet proposed)    View

Page 20293 of 20943, showing 5 records out of 104715 total, starting on record 101461, ending on 101465

Actions