CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36866 | CVE-2008-6749 | Candidate | Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPDirectory 0.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) checkuser and (2) checkpass parameters. | Assigned (20090424) | None (candidate not yet proposed) | View | |
102402 | CVE-2017-5582 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170125) | None (candidate not yet proposed) | View | |
37122 | CVE-2008-7005 | Candidate | include/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary PHP code via the quotes_to_edit parameter. NOTE: this issue has been reported as an unrestricted file upload by some sources, but that is a potential consequence of code execution. | Assigned (20090818) | None (candidate not yet proposed) | View | |
102658 | CVE-2017-5838 | Candidate | The gst_date_time_new_from_iso8601_string function in gst/gstdatetime.c in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a malformed datetime string. | Assigned (20170201) | None (candidate not yet proposed) | View | |
37378 | CVE-2008-7261 | Candidate | The Workplace (aka WP) component in IBM FileNet P8 Application Engine (P8AE) 3.5.1 before 3.5.1-010 records DEBUG messages containing user credentials in the log4j.xml file, which might allow local users to obtain sensitive information by reading this file. | Assigned (20100920) | None (candidate not yet proposed) | View |
Page 219 of 20943, showing 5 records out of 104715 total, starting on record 1091, ending on 1095