CVE List

Id CVE No. Status Description Phase Votes Comments Actions
91904  CVE-2016-5085  Candidate  Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof meters by sniffing the network and then engaging in an authentication handshake.  Assigned (20160526)  None (candidate not yet proposed)    View
26624  CVE-2007-3267  Candidate  Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.01b and earlier allows remote attackers to inject arbitrary web script or HTML via the fromaction parameter in a log action, a different vector than CVE-2007-3235.  Assigned (20070619)  None (candidate not yet proposed)    View
92160  CVE-2016-5341  Candidate  The GPS component in Android before 2016-12-05 allows man-in-the-middle attackers to cause a denial of service (GPS signal-acquisition delay) via an incorrect xtra.bin or xtra2.bin file on a spoofed Qualcomm gpsonextra.net or izatcloud.net host, aka internal bug 31470303 and external bug 211602 (and AndroidID-7225554).  Assigned (20160609)  None (candidate not yet proposed)    View
26880  CVE-2007-3523  Candidate  Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) Ent or (2) Lang parameter.  Assigned (20070703)  None (candidate not yet proposed)    View
92416  CVE-2016-5597  Candidate  Unspecified vulnerability in Oracle Java SE 6u121, 7u111, 8u102; and Java SE Embedded 8u101 allows remote attackers to affect confidentiality via vectors related to Networking.  Assigned (20160616)  None (candidate not yet proposed)    View

Page 41 of 20943, showing 5 records out of 104715 total, starting on record 201, ending on 205

Actions