CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
27900 | CVE-2007-4543 | Candidate | Cross-site scripting (XSS) vulnerability in enter_bug.cgi in Bugzilla 2.17.1 through 2.20.4, 2.22.x before 2.22.3, and 3.x before 3.0.1 allows remote attackers to inject arbitrary web script or HTML via the buildid field in the "guided form." | Assigned (20070827) | None (candidate not yet proposed) | View | |
93436 | CVE-2016-6616 | Candidate | An issue was discovered in phpMyAdmin. In the "User group" and "Designer" features, a user can execute an SQL injection attack against the account of the control user. All 4.6.x versions (prior to 4.6.4) and 4.4.x versions (prior to 4.4.15.8) are affected. | Assigned (20160806) | None (candidate not yet proposed) | View | |
28156 | CVE-2007-4799 | Candidate | The perfstat kernel extension in bos.perf.perfstat in AIX 5.3 does not verify privileges when processing a SET call, which allows local users to cause a denial of service (system hang or crash) via unspecified SET operations. | Assigned (20070910) | None (candidate not yet proposed) | View | |
93692 | CVE-2016-6872 | Candidate | Integer overflow in StringUtil::implode in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors. | Assigned (20160818) | None (candidate not yet proposed) | View | |
28412 | CVE-2007-5055 | Candidate | Multiple directory traversal vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in (1) the admin_home parameter to modules/poll/poll_summary.php or (2) the rootdp parameter to include/db.php. | Assigned (20070924) | None (candidate not yet proposed) | View |
Page 20667 of 20943, showing 5 records out of 104715 total, starting on record 103331, ending on 103335