CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104701  CVE-2017-7881  Candidate  BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in core/admin/modules/developer/_header.php and patched in core/inc/bigtree/admin.php on 2017-04-14.  Assigned (20170415)  None (candidate not yet proposed)    View
39421  CVE-2009-1986  Candidate  Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality via unknown vectors.  Assigned (20090608)  None (candidate not yet proposed)    View
39677  CVE-2009-2242  Candidate  SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execute arbitrary SQL commands via the order parameter.  Assigned (20090627)  None (candidate not yet proposed)    View
39933  CVE-2009-2498  Candidate  Microsoft Windows Media Format Runtime 9.0, 9.5, and 11 and Windows Media Services 9.1 and 2008 do not properly parse malformed headers in Advanced Systems Format (ASF) files, which allows remote attackers to execute arbitrary code via a crafted (1) .asf, (2) .wmv, or (3) .wma file, aka "Windows Media Header Parsing Invalid Free Vulnerability."  Assigned (20090717)  None (candidate not yet proposed)    View
40189  CVE-2009-2754  Candidate  Integer signedness error in the authentication functionality in librpc.dll in the Informix Storage Manager (ISM) Portmapper service (aka portmap.exe), as used in IBM Informix Dynamic Server (IDS) 10.x before 10.00.TC9 and 11.x before 11.10.TC3 and EMC Legato NetWorker, allows remote attackers to execute arbitrary code via a crafted parameter size that triggers a stack-based buffer overflow.  Assigned (20090812)  None (candidate not yet proposed)    View

Page 20764 of 20943, showing 5 records out of 104715 total, starting on record 103816, ending on 103820

Actions