CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104699  CVE-2017-7879  Candidate  SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database.  Assigned (20170414)  None (candidate not yet proposed)    View
39419  CVE-2009-1984  Candidate  Unspecified vulnerability in the Application Install component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to the Patch Administrator.  Assigned (20090608)  None (candidate not yet proposed)    View
39675  CVE-2009-2240  Candidate  Cross-site scripting (XSS) vulnerability in AD2000 free-sw leger (aka Web Conference Room Free) 1.6.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20090627)  None (candidate not yet proposed)    View
39931  CVE-2009-2496  Candidate  Heap-based buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2003 SP3, Office XP Web Components SP3, Office 2003 Web Components SP3, Office 2003 Web Components SP1 for the 2007 Microsoft Office System, Internet Security and Acceleration (ISA) Server 2004 SP3 and 2006 SP1, and Office Small Business Accounting 2006 allows remote attackers to execute arbitrary code via unspecified parameters to unknown methods, aka "Office Web Components Heap Corruption Vulnerability."  Assigned (20090717)  None (candidate not yet proposed)    View
40187  CVE-2009-2752  Candidate  IBM WebSphere Commerce 7.0 does not properly encrypt data in a database, which makes it easier for local users to obtain sensitive information by defeating cryptographic protection mechanisms.  Assigned (20090812)  None (candidate not yet proposed)    View

Page 20605 of 20943, showing 5 records out of 104715 total, starting on record 103021, ending on 103025

Actions