CVE List

Id CVE No. Status Description Phase Votes Comments Actions
29957  CVE-2007-6600  Candidate  PostgreSQL 8.2 before 8.2.6, 8.1 before 8.1.11, 8.0 before 8.0.15, 7.4 before 7.4.19, and 7.3 before 7.3.21 uses superuser privileges instead of table owner privileges for (1) VACUUM and (2) ANALYZE operations within index functions, and supports (3) SET ROLE and (4) SET SESSION AUTHORIZATION within index functions, which allows remote authenticated users to gain privileges.  Assigned (20071231)  None (candidate not yet proposed)    View
95493  CVE-2016-8673  Candidate  Cross-site request forgery (CSRF) vulnerability in the integrated web server on Siemens SIMATIC CP 343-1 Advanced prior to version 3.0.53, SIMATIC CP 443-1 Advanced prior to version 3.2.17, SIMATIC S7-300 CPU, and SIMATIC S7-400 CPU devices allows remote attackers to hijack the authentication of arbitrary users.  Assigned (20161015)  None (candidate not yet proposed)    View
30213  CVE-2008-0096  Candidate  Multiple buffer overflows in Georgia SoftWorks SSH2 Server (GSW_SSHD) 7.01.0003 and earlier allow remote attackers to execute arbitrary code via a (1) a long username, which triggers an overflow in the log function; or (2) a long password.  Assigned (20080107)  None (candidate not yet proposed)    View
95749  CVE-2016-8929  Candidate  IBM Kenexa LMS on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.  Assigned (20161025)  None (candidate not yet proposed)    View
30469  CVE-2008-0352  Candidate  The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6 packet, possibly involving the Jumbo Payload hop-by-hop option (jumbogram).  Assigned (20080117)  None (candidate not yet proposed)    View

Page 466 of 20943, showing 5 records out of 104715 total, starting on record 2326, ending on 2330

Actions