CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102659  CVE-2017-5839  Candidate  The gst_riff_create_audio_caps function in gst-libs/gst/riff/riff-media.c in gst-plugins-base in GStreamer before 1.10.3 does not properly limit recursion, which allows remote attackers to cause a denial of service (stack overflow and crash) via vectors involving nested WAVEFORMATEX.  Assigned (20170201)  None (candidate not yet proposed)    View
37379  CVE-2008-7262  Candidate  Multiple directory traversal vulnerabilities in FTPServer.py in pyftpdlib before 0.3.0 allow remote authenticated users to access arbitrary files and directories via vectors involving a symlink in a pathname to a (1) CWD, (2) DELE, (3) STOR, or (4) RETR command.  Assigned (20101019)  None (candidate not yet proposed)    View
102915  CVE-2017-6095  Candidate  A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/csvexport.php (Unauthenticated) with the GET Parameter: list_id.  Assigned (20170218)  None (candidate not yet proposed)    View
37635  CVE-2009-0200  Candidate  Integer underflow in OpenOffice.org (OOo) before 3.1.1 and StarOffice/StarSuite 7, 8, and 9 might allow remote attackers to execute arbitrary code via crafted records in the document table of a Word document, leading to a heap-based buffer overflow.  Assigned (20090120)  None (candidate not yet proposed)    View
103171  CVE-2017-6351  Candidate  The WePresent WiPG-1500 device with firmware 1.0.3.7 has a manufacturer account that has a hardcoded username / password. Once the device is set to DEBUG mode, an attacker can connect to the device using the telnet protocol and log into the device with the "abarco" hardcoded manufacturer account. This account is not documented, nor is the DEBUG feature or the use of telnetd on port tcp/5885.  Assigned (20170226)  None (candidate not yet proposed)    View

Page 323 of 20943, showing 5 records out of 104715 total, starting on record 1611, ending on 1615

Actions