CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25082  CVE-2007-1725  Candidate  SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL commands via the filename of an uploaded file to the avatar function, as demonstrated by setting admin privileges.  Assigned (20070327)  None (candidate not yet proposed)    View
90618  CVE-2016-3799  Candidate  The MediaTek video driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28175025 and MediaTek internal bug ALPS02693738.  Assigned (20160330)  None (candidate not yet proposed)    View
25338  CVE-2007-1981  Candidate  The safevoid_vsnprintf function in Metamod-P 1.19p29 and earlier on Windows allows remote attackers to cause a denial of service (daemon crash) via a long meta list command.  Assigned (20070411)  None (candidate not yet proposed)    View
90874  CVE-2016-4055  Candidate  The duration function in the moment package before 2.11.2 for Node.js allows remote attackers to cause a denial of service (CPU consumption) via a long string, aka a "regular expression Denial of Service (ReDoS)."  Assigned (20160420)  None (candidate not yet proposed)    View
25594  CVE-2007-2237  Candidate  Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of service (crash) via an ICO file with an InfoHeader containing a Height of zero, which triggers a divide-by-zero error.  Assigned (20070425)  None (candidate not yet proposed)    View

Page 20500 of 20943, showing 5 records out of 104715 total, starting on record 102496, ending on 102500

Actions