CVE List

Id CVE No. Status Description Phase Votes Comments Actions
32767  CVE-2008-2650  Candidate  Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sl parameter to index.php. NOTE: this can be leveraged for remote file execution by including adm.php and then invoking the upload action. NOTE: on 20080601, the vendor patched 3.1 without changing the version number.  Assigned (20080610)  None (candidate not yet proposed)    View
98303  CVE-2017-1483  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161130)  None (candidate not yet proposed)    View
33023  CVE-2008-2906  Candidate  SQL injection vulnerability in lista_anexos.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL commands via the tsk_id parameter.  Assigned (20080630)  None (candidate not yet proposed)    View
98559  CVE-2017-1739  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161130)  None (candidate not yet proposed)    View
33279  CVE-2008-3162  Candidate  Stack-based buffer overflow in the str_read_packet function in libavformat/psxstr.c in FFmpeg before r13993 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted STR file that interleaves audio and video sectors.  Assigned (20080714)  None (candidate not yet proposed)    View

Page 20913 of 20943, showing 5 records out of 104715 total, starting on record 104561, ending on 104565

Actions