CVE List

Id CVE No. Status Description Phase Votes Comments Actions
26110  CVE-2007-2753  Candidate  RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/xice.mdb.  Assigned (20070517)  None (candidate not yet proposed)    View
91646  CVE-2016-4827  Candidate  Cross-site scripting (XSS) vulnerability in the Collne Welcart e-Commerce plugin before 1.8.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2016-4826.  Assigned (20160517)  None (candidate not yet proposed)    View
26366  CVE-2007-3009  Candidate  Format string vulnerability in the MprLogToFile::logEvent function in Mbedthis AppWeb 2.0.5-4, when the build supports logging but the configuration disables logging, allows remote attackers to cause a denial of service (daemon crash) via format string specifiers in the HTTP scheme, as demonstrated by a "GET %n://localhost:80/" request.  Assigned (20070604)  None (candidate not yet proposed)    View
91902  CVE-2016-5083  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160526)  None (candidate not yet proposed)    View
26622  CVE-2007-3265  Candidate  Cross-site scripting (XSS) vulnerability in the Samples component in IBM WebSphere Application Server (WAS) 6.1.0.7 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20070619)  None (candidate not yet proposed)    View

Page 20823 of 20943, showing 5 records out of 104715 total, starting on record 104111, ending on 104115

Actions