CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36607  CVE-2008-6490  Candidate  function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the target filename in the target_file parameter. NOTE: this can be leveraged for code execution by overwriting a PHP file, as demonstrated using function/upload_file.php.  Assigned (20090318)  None (candidate not yet proposed)    View
102143  CVE-2017-5323  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170109)  None (candidate not yet proposed)    View
36863  CVE-2008-6746  Candidate  Cross-site scripting (XSS) vulnerability in the contact display view in Turba Contact Manager H3 before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the contact name.  Assigned (20090423)  None (candidate not yet proposed)    View
102399  CVE-2017-5579  Candidate  Memory leak in the serial_exit_core function in hw/char/serial.c in QEMU (aka Quick Emulator) allows local guest OS privileged users to cause a denial of service (host memory consumption and QEMU process crash) via a large number of device unplug operations.  Assigned (20170125)  None (candidate not yet proposed)    View
37119  CVE-2008-7002  Candidate  PHP 5.2.5 does not enforce (a) open_basedir and (b) safe_mode_exec_dir restrictions for certain functions, which might allow local users to bypass intended access restrictions and call programs outside of the intended directory via the (1) exec, (2) system, (3) shell_exec, (4) passthru, or (5) popen functions, possibly involving pathnames such as "C:" drive notation.  Assigned (20090817)  None (candidate not yet proposed)    View

Page 20919 of 20943, showing 5 records out of 104715 total, starting on record 104591, ending on 104595

Actions