CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25853  CVE-2007-2496  Candidate  The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a long (1) DoOleCommand, (2) FTPDownloadFile, (3) FTPUploadFile, (4) HttpUploadFile, (5) GotoPage, (6) Save, (7) SaveWebFile, (8) HttpDownloadFile, (9) Open, (10) OpenWebFile, (11) SaveAs, or (12) ShowWordStandardDialog property value.  Assigned (20070503)  None (candidate not yet proposed)    View
91389  CVE-2016-4570  Candidate  The mxmlDelete function in mxml-node.c in mxml 2.9, 2.7, and possibly earlier allows remote attackers to cause a denial of service (stack consumption) via crafted xml file.  Assigned (20160509)  None (candidate not yet proposed)    View
26109  CVE-2007-2752  Candidate  SQL injection vulnerability in devami.asp in RunawaySoft Haber portal 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20070517)  None (candidate not yet proposed)    View
91645  CVE-2016-4826  Candidate  Cross-site scripting (XSS) vulnerability in the Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-4827.  Assigned (20160517)  None (candidate not yet proposed)    View
26365  CVE-2007-3008  Candidate  Mbedthis AppWeb before 2.2.2 enables the HTTP TRACE method, which has unspecified impact probably related to remote information leaks and cross-site tracing (XST) attacks, a related issue to CVE-2004-2320 and CVE-2005-3398.  Assigned (20070604)  None (candidate not yet proposed)    View

Page 20743 of 20943, showing 5 records out of 104715 total, starting on record 103711, ending on 103715

Actions