CVE List

Id CVE No. Status Description Phase Votes Comments Actions
90616  CVE-2016-3797  Candidate  The Qualcomm Wi-Fi driver in Android before 2016-07-05 on Nexus 5X devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28085680 and Qualcomm internal bug CR1001450.  Assigned (20160330)  None (candidate not yet proposed)    View
25336  CVE-2007-1979  Candidate  SQL injection vulnerability in index.php in the PopnupBlog 2.52 and earlier module for Xoops allows remote attackers to execute arbitrary SQL commands via the postid parameter, possibly involving the get_blogid_from_postid function in class/PopnupBlogUtils.php. NOTE: later versions such as 3.03 and 3.05 might also be affected.  Assigned (20070411)  None (candidate not yet proposed)    View
90872  CVE-2016-4053  Candidate  Squid 3.x before 3.5.17 and 4.x before 4.0.9 allow remote attackers to obtain sensitive stack layout information via crafted Edge Side Includes (ESI) responses, related to incorrect use of assert and compiler optimization.  Assigned (20160420)  None (candidate not yet proposed)    View
25592  CVE-2007-2235  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in PunBB 1.2.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Referer HTTP header to misc.php or the (2) category name when deleting a category in admin_categories.php.  Assigned (20070425)  None (candidate not yet proposed)    View
91128  CVE-2016-4309  Candidate  Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers to hijack web sessions via the PHPSESSID parameter.  Assigned (20160427)  None (candidate not yet proposed)    View

Page 20344 of 20943, showing 5 records out of 104715 total, starting on record 101716, ending on 101720

Actions