CVE List

Id CVE No. Status Description Phase Votes Comments Actions
88579  CVE-2016-1760  Candidate  The XPC Services API in LaunchServices in Apple iOS before 9.3 allows attackers to bypass intended event-handler restrictions and modify an arbitrary app"s events via a crafted app.  Assigned (20160113)  None (candidate not yet proposed)    View
23299  CVE-2006-7195  Candidate  Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.  Assigned (20070418)  None (candidate not yet proposed)    View
88835  CVE-2016-2016  Candidate  Base-VxFS-50 B.05.00.01 through B.05.00.02, Base-VxFS-501 B.05.01.0 through B.05.01.03, and Base-VxFS-51 B.05.10.00 through B.05.10.02 on HPE HP-UX 11iv3 with VxFS 5.0, VxFS 5.0.1, and VxFS 5.1SP1 mishandles ACL inheritance for default:class: entries, default:other: entries, and default:user: entries, which allows local users to bypass intended access restrictions by leveraging the configuration of a parent directory.  Assigned (20160122)  None (candidate not yet proposed)    View
23555  CVE-2007-0198  Candidate  The JTapi Gateway process in Cisco Unified Contact Center Enterprise, Unified Contact Center Hosted, IP Contact Center Enterprise, and Cisco IP Contact Center Hosted 5.0 through 7.1 allows remote attackers to cause a denial of service (repeated process restart) via a certain TCP session on the JTapi server port.  Assigned (20070110)  None (candidate not yet proposed)    View
89091  CVE-2016-2272  Candidate  Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to have an unspecified impact via a modified cookie.  Assigned (20160209)  None (candidate not yet proposed)    View

Page 301 of 20943, showing 5 records out of 104715 total, starting on record 1501, ending on 1505

Actions