CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
28420 | CVE-2007-5063 | Candidate | Adam Scheinberg Flip 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing login credentials via a direct request for var/users.txt. | Assigned (20070924) | None (candidate not yet proposed) | View | |
93956 | CVE-2016-7136 | Candidate | z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted GET request. | Assigned (20160905) | None (candidate not yet proposed) | View | |
28676 | CVE-2007-5319 | Candidate | Unspecified vulnerability in the vuidmice STREAMS modules in Sun Solaris 8, 9, and 10 allows local users with console (/dev/console) access to cause a denial of service ("unusable" system console) via unspecified vectors. | Assigned (20071009) | None (candidate not yet proposed) | View | |
94212 | CVE-2016-7392 | Candidate | Heap-based buffer overflow in the pstoedit_suffix_table_init function in output-pstoedit.c in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted bmp image file. | Assigned (20160909) | None (candidate not yet proposed) | View | |
28932 | CVE-2007-5575 | Candidate | Cross-site request forgery (CSRF) vulnerability in 1024 CMS 1.2.5 allows remote attackers to perform some actions as administrators, as demonstrated by (1) an unspecified action that creates a file containing PHP code and (2) unspecified use of the forum component. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | Assigned (20071018) | None (candidate not yet proposed) | View |
Page 367 of 20943, showing 5 records out of 104715 total, starting on record 1831, ending on 1835