CVE List

Id CVE No. Status Description Phase Votes Comments Actions
91640  CVE-2016-4821  Candidate  I-O DATA DEVICE ETX-R devices allow remote attackers to cause a denial of service (web-server crash) via unspecified vectors.  Assigned (20160517)  None (candidate not yet proposed)    View
26360  CVE-2007-3003  Candidate  Multiple SQL injection vulnerabilities in myBloggie 2.1.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id or (2) year parameter to index.php in a viewuser action, different vectors than CVE-2005-1500 and CVE-2005-4225.  Assigned (20070604)  None (candidate not yet proposed)    View
91896  CVE-2016-5077  Candidate  Netikus EventSentry before 3.2.1.44 has XSS via SNMP.  Assigned (20160526)  None (candidate not yet proposed)    View
26616  CVE-2007-3259  Candidate  Calendarix 0.7.20070307 allows remote attackers to obtain sensitive information via (1) an invalid month[] parameter to calendar.php, (2) an invalid catview[] parameter to cal_week.php in a week operation, (3) an invalid ycyear[] parameter to yearcal.php, or (4) a direct request to cal_functions.inc.php, which reveals the installation path in various error messages.  Assigned (20070619)  None (candidate not yet proposed)    View
92152  CVE-2016-5333  Candidate  VMware Photos OS OVA 1.0 before 2016-08-14 has a default SSH public key in an authorized_keys file, which allows remote attackers to obtain SSH access by leveraging knowledge of the private key.  Assigned (20160607)  None (candidate not yet proposed)    View

Page 20327 of 20943, showing 5 records out of 104715 total, starting on record 101631, ending on 101635

Actions