CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25592  CVE-2007-2235  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in PunBB 1.2.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Referer HTTP header to misc.php or the (2) category name when deleting a category in admin_categories.php.  Assigned (20070425)  None (candidate not yet proposed)    View
91128  CVE-2016-4309  Candidate  Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter.  Assigned (20160427)  None (candidate not yet proposed)    View
25848  CVE-2007-2491  Candidate  The PIIX4 power management subsystem in EMC VMware Workstation 5.5.3.34685 and VMware Server 1.0.1.29996 allows local users to write to arbitrary memory locations via a crafted poke to I/O port 0x1004, triggering a denial of service (virtual machine crash) or other unspecified impact, a related issue to CVE-2007-1337.  Assigned (20070503)  None (candidate not yet proposed)    View
91384  CVE-2016-4565  Candidate  The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface.  Assigned (20160507)  None (candidate not yet proposed)    View
26104  CVE-2007-2747  Candidate  Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to the /browse URI.  Assigned (20070517)  None (candidate not yet proposed)    View

Page 20326 of 20943, showing 5 records out of 104715 total, starting on record 101626, ending on 101630

Actions