CVE List

Id CVE No. Status Description Phase Votes Comments Actions
91388  CVE-2016-4569  Candidate  The snd_timer_user_params function in sound/core/timer.c in the Linux kernel through 4.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel stack memory via crafted use of the ALSA timer interface.  Assigned (20160509)  None (candidate not yet proposed)    View
26108  CVE-2007-2751  Candidate  Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP code via a URL in the format_menue parameter to (1) admin/inc/change_action.php or (2) admin/inc/add.php.  Assigned (20070517)  None (candidate not yet proposed)    View
91644  CVE-2016-4825  Candidate  The Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via crafted serialized data.  Assigned (20160517)  None (candidate not yet proposed)    View
26364  CVE-2007-3007  Candidate  PHP 5 before 5.2.3 does not enforce the open_basedir or safe_mode restriction in certain cases, which allows context-dependent attackers to determine the existence of arbitrary files by checking if the readfile function returns a string. NOTE: this issue might also involve the realpath function.  Assigned (20070604)  None (candidate not yet proposed)    View
91900  CVE-2016-5081  Candidate  ZModo ZP-NE14-S and ZP-IBH-13W devices have a hardcoded root password, which makes it easier for remote attackers to obtain access via a TELNET session.  Assigned (20160526)  None (candidate not yet proposed)    View

Page 20664 of 20943, showing 5 records out of 104715 total, starting on record 103316, ending on 103320

Actions