CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
90874 | CVE-2016-4055 | Candidate | The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)." | Assigned (20160420) | None (candidate not yet proposed) | View | |
25594 | CVE-2007-2237 | Candidate | Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error. | Assigned (20070425) | None (candidate not yet proposed) | View | |
91130 | CVE-2016-4311 | Candidate | Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request. | Assigned (20160427) | None (candidate not yet proposed) | View | |
25850 | CVE-2007-2493 | Candidate | PHP remote file inclusion vulnerability in faq.php in the FAQ & RULES 2.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter. | Assigned (20070503) | None (candidate not yet proposed) | View | |
91386 | CVE-2016-4567 | Candidate | Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn." | Assigned (20160507) | None (candidate not yet proposed) | View |
Page 20480 of 20943, showing 5 records out of 104715 total, starting on record 102396, ending on 102400