CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
27397 | CVE-2007-4040 | Candidate | Argument injection vulnerability involving Microsoft Outlook and Outlook Express, when certain URIs are registered, allows remote attackers to conduct cross-browser scripting attacks and execute arbitrary commands via shell metacharacters in an unspecified URI, which are inserted into the command line when invoking the handling process, a similar issue to CVE-2007-3670. | Assigned (20070727) | None (candidate not yet proposed) | View | |
92933 | CVE-2016-6113 | Candidate | IBM Verse is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | Assigned (20160629) | None (candidate not yet proposed) | View | |
27653 | CVE-2007-4296 | Candidate | Unspecified vulnerability in assp.pl in Anti-Spam SMTP Proxy Server (ASSP) 1.3.3 has unknown impact and attack vectors. | Assigned (20070810) | None (candidate not yet proposed) | View | |
93189 | CVE-2016-6369 | Candidate | Cisco AnyConnect Secure Mobility Client before 4.2.05015 and 4.3.x before 4.3.02039 mishandles pathnames, which allows local users to gain privileges via a crafted INF file, aka Bug ID CSCuz92464. | Assigned (20160726) | None (candidate not yet proposed) | View | |
27909 | CVE-2007-4552 | Candidate | SQL injection vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary SQL commands via the blockpage parameter. NOTE: as of 20070827, the vendor has made conflicting statements regarding whether this issue exists or not. | Assigned (20070827) | None (candidate not yet proposed) | View |
Page 462 of 20943, showing 5 records out of 104715 total, starting on record 2306, ending on 2310