CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
90616 | CVE-2016-3797 | Candidate | The Qualcomm Wi-Fi driver in Android before 2016-07-05 on Nexus 5X devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28085680 and Qualcomm internal bug CR1001450. | Assigned (20160330) | None (candidate not yet proposed) | View | |
25336 | CVE-2007-1979 | Candidate | SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the postid parameter, possibly involving the get_blogid_from_postid function in class/PopnupBlogUtils.php. NOTE: later versions such as 3.03 and 3.05 might also be affected. | Assigned (20070411) | None (candidate not yet proposed) | View | |
90872 | CVE-2016-4053 | Candidate | Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization. | Assigned (20160420) | None (candidate not yet proposed) | View | |
25592 | CVE-2007-2235 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in PunBB 1.2.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Referer HTTP header to misc.php or the (2) category name when deleting a category in admin_categories.php. | Assigned (20070425) | None (candidate not yet proposed) | View | |
91128 | CVE-2016-4309 | Candidate | Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter. | Assigned (20160427) | None (candidate not yet proposed) | View |
Page 20340 of 20943, showing 5 records out of 104715 total, starting on record 101696, ending on 101700