CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
25592 | CVE-2007-2235 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in PunBB 1.2.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Referer HTTP header to misc.php or the (2) category name when deleting a category in admin_categories.php. | Assigned (20070425) | None (candidate not yet proposed) | View | |
91128 | CVE-2016-4309 | Candidate | Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter. | Assigned (20160427) | None (candidate not yet proposed) | View | |
25848 | CVE-2007-2491 | Candidate | The PIIX4 power management subsystem in EMC VMware Workstation 5.5.3.34685 and VMware Server 1.0.1.29996 allows local users to write to arbitrary memory locations via a crafted poke to I/O port 0x1004, triggering a denial of service (virtual machine crash) or other unspecified impact, a related issue to CVE-2007-1337. | Assigned (20070503) | None (candidate not yet proposed) | View | |
91384 | CVE-2016-4565 | Candidate | The InfiniBand (aka IB) stack in the Linux kernel before 4.5.3 incorrectly relies on the write system call, which allows local users to cause a denial of service (kernel memory write operation) or possibly have unspecified other impact via a uAPI interface. | Assigned (20160507) | None (candidate not yet proposed) | View | |
26104 | CVE-2007-2747 | Candidate | Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to the /browse URI. | Assigned (20070517) | None (candidate not yet proposed) | View |
Page 20326 of 20943, showing 5 records out of 104715 total, starting on record 101626, ending on 101630