CVE List

Id CVE No. Status Description Phase Votes Comments Actions
27900  CVE-2007-4543  Candidate  Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla 2.17.1 through 2.20.4, 2.22.x before 2.22.3, and 3.x before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the buildid field in the "guided form."  Assigned (20070827)  None (candidate not yet proposed)    View
93436  CVE-2016-6616  Candidate  An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected.  Assigned (20160806)  None (candidate not yet proposed)    View
28156  CVE-2007-4799  Candidate  The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations.  Assigned (20070910)  None (candidate not yet proposed)    View
93692  CVE-2016-6872  Candidate  Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.  Assigned (20160818)  None (candidate not yet proposed)    View
28412  CVE-2007-5055  Candidate  Multiple directory traversal vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the admin_home parameter to modules/poll/poll_summary.php or (2) the rootdp parameter to include/db.php.  Assigned (20070924)  None (candidate not yet proposed)    View

Page 20667 of 20943, showing 5 records out of 104715 total, starting on record 103331, ending on 103335

Actions