CVE List

Id CVE No. Status Description Phase Votes Comments Actions
38140  CVE-2009-0705  Candidate  SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the newsid parameter.  Assigned (20090223)  None (candidate not yet proposed)    View
103676  CVE-2017-6856  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170313)  None (candidate not yet proposed)    View
38396  CVE-2009-0961  Candidate  The Mail component in Apple iPhone OS 1.0 through 2.2.1 and iPhone OS for iPod touch 1.1 through 2.2.1 dismisses the call approval dialog when another alert appears, which might allow remote attackers to force the iPhone to place a call without user approval by causing an application to trigger an alert.  Assigned (20090318)  None (candidate not yet proposed)    View
103932  CVE-2017-7112  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170317)  None (candidate not yet proposed)    View
38652  CVE-2009-1217  Candidate  Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers to cause a denial of service (stack corruption and application termination) via a crafted EMF file that triggers an integer overflow, as demonstrated by voltage-exploit.emf, aka the "Microsoft GdiPlus EMF GpFont.SetData integer overflow."  Assigned (20090401)  None (candidate not yet proposed)    View

Page 20683 of 20943, showing 5 records out of 104715 total, starting on record 103411, ending on 103415

Actions