CVE List

Id CVE No. Status Description Phase Votes Comments Actions
90874  CVE-2016-4055  Candidate  The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."  Assigned (20160420)  None (candidate not yet proposed)    View
25594  CVE-2007-2237  Candidate  Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.  Assigned (20070425)  None (candidate not yet proposed)    View
91130  CVE-2016-4311  Candidate  Cross-site request forgery (CSRF) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 allows remote attackers to hijack the authentication of privileged users for requests that process XACML requests via an entitlement/eval-policy-submit.jsp request.  Assigned (20160427)  None (candidate not yet proposed)    View
25850  CVE-2007-2493  Candidate  PHP remote file inclusion vulnerability in faq.php in the FAQ & RULES 2.0.0 and earlier module for mxBB allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.  Assigned (20070503)  None (candidate not yet proposed)    View
91386  CVE-2016-4567  Candidate  Cross-site scripting (XSS) vulnerability in flash/FlashMediaElement.as in MediaElement.js before 2.21.0, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via an obfuscated form of the jsinitfunction parameter, as demonstrated by "jsinitfunctio%gn."  Assigned (20160507)  None (candidate not yet proposed)    View

Page 20480 of 20943, showing 5 records out of 104715 total, starting on record 102396, ending on 102400

Actions