CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36860 | CVE-2008-6743 | Candidate | RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verified cookie to an arbitrary value and performing a direct request to (1) delete.php, (2) edit-submit.php, (3) edit.php, (4) submit.php, and (5) update.php, which bypasses the security check that is performed by verify.php. | Assigned (20090422) | None (candidate not yet proposed) | View | |
102396 | CVE-2017-5576 | Candidate | Integer overflow in the vc4_get_bcl function in drivers/gpu/drm/vc4/vc4_gem.c in the VideoCore DRM driver in the Linux kernel before 4.9.7 allows local users to cause a denial of service or possibly have unspecified other impact via a crafted size value in a VC4_SUBMIT_CL ioctl call. | Assigned (20170124) | None (candidate not yet proposed) | View | |
37116 | CVE-2008-6999 | Candidate | phpAuction 3.2, and possibly 3.3.0 GPL Basic edition, allows remote attackers to obtain configuration information via a direct request to phpinfo.php, which calls the phpinfo function. | Assigned (20090817) | None (candidate not yet proposed) | View | |
102652 | CVE-2017-5832 | Candidate | Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user"s email address. | Assigned (20170201) | None (candidate not yet proposed) | View | |
37372 | CVE-2008-7255 | Candidate | login_screen.tcl in aMSN (aka Alvaro"s Messenger) before 0.97.1 saves a password after logout, which allows physically proximate attackers to hijack a session by visiting an unattended workstation. | Assigned (20100420) | None (candidate not yet proposed) | View |
Page 20681 of 20943, showing 5 records out of 104715 total, starting on record 103401, ending on 103405