CVE List

Id CVE No. Status Description Phase Votes Comments Actions
89603  CVE-2016-2784  Candidate  CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduct cache poisoning attacks, modify links, and conduct cross-site scripting (XSS) attacks via a crafted HTTP Host header in a request.  Assigned (20160229)  None (candidate not yet proposed)    View
24323  CVE-2007-0966  Candidate  Cisco Firewall Services Module (FWSM) 3.x before 3.1(3.11), when the HTTPS server is enabled, allows remote attackers to cause a denial of service (device reboot) via certain HTTPS traffic.  Assigned (20070215)  None (candidate not yet proposed)    View
89859  CVE-2016-3040  Candidate  IBM WebSphere Application Server (WAS) Liberty, as used in IBM Security Privileged Identity Manager (ISPIM) Virtual Appliance 2.x before 2.0.2 FP8, allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.  Assigned (20160309)  None (candidate not yet proposed)    View
24579  CVE-2007-1222  Candidate  Parallels Desktop for Mac before 20070216 implements Drag and Drop by sharing the entire host filesystem as the .psf share, which allows local users of the guest operating system to write arbitrary files to the host filesystem, and execute arbitrary code via launchd by writing a plist file to a LaunchAgents directory.  Assigned (20070302)  None (candidate not yet proposed)    View
90115  CVE-2016-3296  Candidate  The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability."  Assigned (20160315)  None (candidate not yet proposed)    View

Page 280 of 20943, showing 5 records out of 104715 total, starting on record 1396, ending on 1400

Actions