CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
31235 | CVE-2008-1118 | Candidate | Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging information fields taken from packets from a remote peer, which allows remote attackers to generate crafted log entries, and possibly avoid detection of attacks, via modified (1) computer name, (2) user name, and (3) IP address fields. | Assigned (20080303) | None (candidate not yet proposed) | View | |
96771 | CVE-2016-9951 | Candidate | An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `RespawnCommand` or `ProcCmdline` fields. This command will be executed if a user clicks the Relaunch button on the Apport prompt from the malicious crash file. The fix is to only show the Relaunch button on Apport crash files generated by local systems. The Relaunch button will be hidden when crash files are opened directly in Apport-GTK. | Assigned (20161214) | None (candidate not yet proposed) | View | |
31491 | CVE-2008-1374 | Candidate | Integer overflow in pdftops filter in CUPS in Red Hat Enterprise Linux 3 and 4, when running on 64-bit platforms, allows remote attackers to execute arbitrary code via a crafted PDF file. NOTE: this issue is due to an incomplete fix for CVE-2004-0888. | Assigned (20080318) | None (candidate not yet proposed) | View | |
97027 | CVE-2017-0208 | Candidate | An information disclosure vulnerability exists in Microsoft Edge when the Chakra scripting engine does not properly handle objects in memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user"s system, a.k.a. "Scripting Engine Information Disclosure Vulnerability." | Assigned (20160909) | None (candidate not yet proposed) | View | |
31747 | CVE-2008-1630 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in CuteFlow 1.5.0 and 2.10.0 allow remote attackers to inject arbitrary web script or HTML via the language parameter to (1) page/showcirculation.php; and (2) edittemplate_step2.php, (3) showfields.php, (4) showuser.php, (5) editmailinglist_step1.php, and (6) showtemplates.php in pages/. | Assigned (20080402) | None (candidate not yet proposed) | View |
Page 291 of 20943, showing 5 records out of 104715 total, starting on record 1451, ending on 1455