CVE List

Id CVE No. Status Description Phase Votes Comments Actions
86010  CVE-2015-8733  Candidate  The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.9 and 2.0.x before 2.0.1 does not validate the relationships between record lengths and record header lengths, which allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted file.  Assigned (20160103)  None (candidate not yet proposed)    View
20730  CVE-2006-4626  Candidate  Heap-based buffer overflow in alwil avast! Anti-virus Engine before 4.7.869 allows remote attackers to execute arbitrary code via a crafted LHA file that contains extended headers with file and directory names whose concatenation triggers the overflow.  Assigned (20060907)  None (candidate not yet proposed)    View
86266  CVE-2015-8989  Candidate  Unsalted password vulnerability in the Enterprise Manager (web portal) component in Intel Security McAfee Vulnerability Manager (MVM) 7.5.8 and earlier allows attackers to more easily decrypt user passwords via brute force attacks against the database.  Assigned (20170227)  None (candidate not yet proposed)    View
20986  CVE-2006-4882  Candidate  SQL injection vulnerability in Review.asp in Julian Roberts Charon Cart 3 allows remote attackers to execute arbitrary SQL commands via the ProductID parameter.  Assigned (20060919)  None (candidate not yet proposed)    View
86522  CVE-2016-0226  Candidate  The client implementation in IBM Informix Dynamic Server 11.70.xCn on Windows does not properly restrict access to the (1) nsrd, (2) nsrexecd, and (3) portmap executable files, which allows local users to gain privileges via a Trojan horse file.  Assigned (20151208)  None (candidate not yet proposed)    View

Page 20493 of 20943, showing 5 records out of 104715 total, starting on record 102461, ending on 102465

Actions