CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
88063 | CVE-2016-1244 | Candidate | The extractTree function in unADF allows remote attackers to execute arbitrary code via shell metacharacters in a directory name in an adf file. | Assigned (20151227) | None (candidate not yet proposed) | View | |
22783 | CVE-2006-6679 | Candidate | Pedro Lineu Orso chetcpasswd before 2.4 relies on the X-Forwarded-For HTTP header when verifying a client"s status on an IP address ACL, which allows remote attackers to gain unauthorized access by spoofing this header. | Assigned (20061221) | None (candidate not yet proposed) | View | |
88319 | CVE-2016-1500 | Candidate | ownCloud Server before 7.0.12, 8.0.x before 8.0.10, 8.1.x before 8.1.5, and 8.2.x before 8.2.2, when the "file_versions" application is enabled, does not properly check the return value of getOwner, which allows remote authenticated users to read the files with names starting with ".v" and belonging to a sharing user by leveraging an incoming share. | Assigned (20160106) | None (candidate not yet proposed) | View | |
23039 | CVE-2006-6935 | Candidate | SQL injection vulnerability in the login component in Portix-PHP 0.4.2 allows remote attackers to execute arbitrary SQL commands via the username and passwd (password) fields. | Assigned (20070116) | None (candidate not yet proposed) | View | |
88575 | CVE-2016-1756 | Candidate | The kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app. | Assigned (20160113) | None (candidate not yet proposed) | View |
Page 20861 of 20943, showing 5 records out of 104715 total, starting on record 104301, ending on 104305