CVE List

Id CVE No. Status Description Phase Votes Comments Actions
37123  CVE-2008-7006  Candidate  Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and download a backup of the database via a direct request to admin/backupdb.php.  Assigned (20090818)  None (candidate not yet proposed)    View
102659  CVE-2017-5839  Candidate  The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 does not properly limit recursion, which allows remote attackers to cause a denial of service (stack overflow and crash) via vectors involving nested WAVEFORMATEX.  Assigned (20170201)  None (candidate not yet proposed)    View
37379  CVE-2008-7262  Candidate  Multiple directory traversal vulnerabilities in FTPServer.py in pyftpdlib before 0.3.0 allow remote authenticated users to access arbitrary files and directories via vectors involving a symlink in a pathname to a (1) CWD, (2) DELE, (3) STOR, or (4) RETR command.  Assigned (20101019)  None (candidate not yet proposed)    View
102915  CVE-2017-6095  Candidate  A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/csvexport.php (Unauthenticated) with the GET Parameter: list_id.  Assigned (20170218)  None (candidate not yet proposed)    View
37635  CVE-2009-0200  Candidate  Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow.  Assigned (20090120)  None (candidate not yet proposed)    View

Page 296 of 20943, showing 5 records out of 104715 total, starting on record 1476, ending on 1480

Actions