CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36860  CVE-2008-6743  Candidate  RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php.  Assigned (20090422)  None (candidate not yet proposed)    View
102396  CVE-2017-5576  Candidate  Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted size value in a VC4_SUBMIT_CL ioctl call.  Assigned (20170124)  None (candidate not yet proposed)    View
37116  CVE-2008-6999  Candidate  phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function.  Assigned (20090817)  None (candidate not yet proposed)    View
102652  CVE-2017-5832  Candidate  Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user"s email address.  Assigned (20170201)  None (candidate not yet proposed)    View
37372  CVE-2008-7255  Candidate  login_screen.tcl in aMSN (aka Alvaro"s Messenger) before 0.97.1 saves a password after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation.  Assigned (20100420)  None (candidate not yet proposed)    View

Page 20681 of 20943, showing 5 records out of 104715 total, starting on record 103401, ending on 103405

Actions