CVE List

Id CVE No. Status Description Phase Votes Comments Actions
28420  CVE-2007-5063  Candidate  Adam Scheinberg Flip 3.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a file containing login credentials via a direct request for var/users.txt.  Assigned (20070924)  None (candidate not yet proposed)    View
93956  CVE-2016-7136  Candidate  z3c.form in Plone CMS 5.x through 5.0.6 and 4.x through 4.3.11 allows remote attackers to conduct cross-site scripting (XSS) attacks via a crafted GET request.  Assigned (20160905)  None (candidate not yet proposed)    View
28676  CVE-2007-5319  Candidate  Unspecified vulnerability in the vuidmice STREAMS modules in Sun Solaris 8, 9, and 10 allows local users with console (/dev/console) access to cause a denial of service ("unusable" system console) via unspecified vectors.  Assigned (20071009)  None (candidate not yet proposed)    View
94212  CVE-2016-7392  Candidate  Heap-based buffer overflow in the pstoedit_suffix_table_init function in output-pstoedit.c in AutoTrace 0.31.1 allows remote attackers to cause a denial of service (out-of-bounds write) via a crafted bmp image file.  Assigned (20160909)  None (candidate not yet proposed)    View
28932  CVE-2007-5575  Candidate  Cross-site request forgery (CSRF) vulnerability in 1024 CMS 1.2.5 allows remote attackers to perform some actions as administrators, as demonstrated by (1) an unspecified action that creates a file containing PHP code and (2) unspecified use of the forum component. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20071018)  None (candidate not yet proposed)    View

Page 367 of 20943, showing 5 records out of 104715 total, starting on record 1831, ending on 1835

Actions