CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
91644 | CVE-2016-4825 | Candidate | The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted serialized data. | Assigned (20160517) | None (candidate not yet proposed) | View | |
26364 | CVE-2007-3007 | Candidate | PHP 5 before 5.2.3 does not enforce the open_basedir or safe_mode restriction in certain cases, which allows context-dependent attackers to determine the existence of arbitrary files by checking if the readfile function returns a string. NOTE: this issue might also involve the realpath function. | Assigned (20070604) | None (candidate not yet proposed) | View | |
91900 | CVE-2016-5081 | Candidate | ZModo ZP-NE14-S and ZP-IBH-13W devices have a hardcoded root password, which makes it easier for remote attackers to obtain access via a TELNET session. | Assigned (20160526) | None (candidate not yet proposed) | View | |
26620 | CVE-2007-3263 | Candidate | Unspecified vulnerability in the Default Messaging Component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier has unknown impact and attack vectors, related to "incorrect authorization on a remote interface to the SDO repository." | Assigned (20070619) | None (candidate not yet proposed) | View | |
92156 | CVE-2016-5337 | Candidate | The megasas_ctrl_get_info function in hw/scsi/megasas.c in QEMU allows local guest OS administrators to obtain sensitive host memory information via vectors related to reading device control information. | Assigned (20160608) | None (candidate not yet proposed) | View |
Page 20635 of 20943, showing 5 records out of 104715 total, starting on record 103171, ending on 103175