CVE List

Id CVE No. Status Description Phase Votes Comments Actions
30712  CVE-2008-0595  Candidate  dbus-daemon in D-Bus before 1.0.3, and 1.1.x before 1.1.20, recognizes send_interface attributes in allow directives in the security policy only for fully qualified method calls, which allows local users to bypass intended access restrictions via a method call with a NULL interface.  Assigned (20080205)  None (candidate not yet proposed)    View
96248  CVE-2016-9428  Candidate  An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. Heap-based buffer overflow in the addMultirowsForm function in w3m allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTML page.  Assigned (20161118)  None (candidate not yet proposed)    View
30968  CVE-2008-0851  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.4 allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to inscription.php, (2) courseCode parameter to main/calendar/myagenda.php, (3) category parameter to main/admin/course_category.php, (4) message parameter to main/admin/session_list.php in a show_message action, and (5) an avatar image to main/auth/profile.php.  Assigned (20080220)  None (candidate not yet proposed)    View
96504  CVE-2016-9684  Candidate  The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the "viewcert" CGI (/cgi-bin/viewcert) component responsible for processing SSL certificate information. The CGI application doesn"t properly escape the information it"s passed in the "CERT" variable before a call to system() is performed - allowing for remote command injection. Exploitation of this vulnerability yields shell access to the remote machine under the nobody user account.  Assigned (20161130)  None (candidate not yet proposed)    View
31224  CVE-2008-1107  Candidate  Multiple stack-based buffer overflows in the Danske Bank e-Sec Control Module ActiveX control (DanskeSikker.ocx) 3.1.0.48, and possibly earlier versions, allow remote attackers to execute arbitrary code via long arguments to unspecified methods, which are not properly handled by a logging function.  Assigned (20080229)  None (candidate not yet proposed)    View

Page 20334 of 20943, showing 5 records out of 104715 total, starting on record 101666, ending on 101670

Actions