CVE List

Id CVE No. Status Description Phase Votes Comments Actions
95491  CVE-2016-8671  Candidate  The pstm_exptmod function in MatrixSSL 3.8.6 and earlier does not properly perform modular exponentiation, which might allow remote attackers to predict the secret key via unspecified vectors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2016-6887.  Assigned (20161015)  None (candidate not yet proposed)    View
30211  CVE-2008-0094  Candidate  Multiple directory traversal vulnerabilities in MODx Content Management System 0.9.6.1 allow remote attackers to (1) include and execute arbitrary local files via a .. (dot dot) in the as_language parameter to assets/snippets/AjaxSearch/AjaxSearch.php, reached through index-ajax.php; and (2) read arbitrary local files via a .. (dot dot) in the file parameter to assets/js/htcmime.php.  Assigned (20080107)  None (candidate not yet proposed)    View
95747  CVE-2016-8927  Candidate  IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118540.  Assigned (20161025)  None (candidate not yet proposed)    View
30467  CVE-2008-0350  Candidate  admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows remote attackers to gain administrative privileges and make arbitrary configuration changes.  Assigned (20080117)  None (candidate not yet proposed)    View
96003  CVE-2016-9183  Candidate  In /framework/modules/ecommerce/controllers/orderController.php of Exponent CMS 2.4.0, untrusted input is passed into selectObjectsBySql. The method selectObjectsBySql of class mysqli_database uses the injectProof method to prevent SQL injection, but this filter can be bypassed easily: it only sanitizes user input if there are odd numbers of " or " characters. Impact is Information Disclosure.  Assigned (20161104)  None (candidate not yet proposed)    View

Page 285 of 20943, showing 5 records out of 104715 total, starting on record 1421, ending on 1425

Actions