CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96250  CVE-2016-9430  Candidate  An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page.  Assigned (20161118)  None (candidate not yet proposed)    View
30970  CVE-2008-0853  Candidate  SQL injection vulnerability in the com_detail component for Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. NOTE: this issue might be site-specific. If so, it should not be included in CVE.  Assigned (20080220)  None (candidate not yet proposed)    View
96506  CVE-2016-9686  Candidate  The Puppet Communications Protocol (PCP) Broker incorrectly validates message header sizes. An attacker could use this to crash the PCP Broker, preventing commands from being sent to agents. This is resolved in Puppet Enterprise 2016.4.3 and 2016.5.2.  Assigned (20161130)  None (candidate not yet proposed)    View
31226  CVE-2008-1109  Candidate  Heap-based buffer overflow in Evolution 2.22.1 allows user-assisted remote attackers to execute arbitrary code via a long DESCRIPTION property in an iCalendar attachment, which is not properly handled during a reply in the calendar view (aka the Calendars window).  Assigned (20080229)  None (candidate not yet proposed)    View
96762  CVE-2016-9942  Candidate  Heap-based buffer overflow in ultra.c in LibVNCClient in LibVNCServer before 0.9.11 allows remote servers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted FramebufferUpdate message with the Ultra type tile, such that the LZO payload decompressed length exceeds what is specified by the tile dimensions.  Assigned (20161213)  None (candidate not yet proposed)    View

Page 20509 of 20943, showing 5 records out of 104715 total, starting on record 102541, ending on 102545

Actions