CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102405 | CVE-2017-5585 | Candidate | OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row_based config option is false, does not properly restrict DQL hints, which allows remote authenticated users to conduct DQL injection attacks and execute arbitrary DML or DDL commands via a crafted request. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2520. | Assigned (20170125) | None (candidate not yet proposed) | View | |
37125 | CVE-2008-7008 | Candidate | HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a direct request to admin/backup/db. | Assigned (20090818) | None (candidate not yet proposed) | View | |
102661 | CVE-2017-5841 | Candidate | The gst_avi_demux_parse_ncdt function in gst/avi/gstavidemux.c in gst-plugins-good in GStreamer before 1.10.3 allows remote attackers to cause a denial of service (out-of-bounds heap read) via vectors involving ncdt tags. | Assigned (20170201) | None (candidate not yet proposed) | View | |
37381 | CVE-2008-7264 | Candidate | The ftp_QUIT function in ftpserver.py in pyftpdlib before 0.5.0 allows remote authenticated users to cause a denial of service (file descriptor exhaustion and daemon outage) by sending a QUIT command during a disallowed data-transfer attempt. | Assigned (20101019) | None (candidate not yet proposed) | View | |
102917 | CVE-2017-6097 | Candidate | A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requires authentication to Wordpress admin) with the POST Parameter: camp_id. | Assigned (20170218) | None (candidate not yet proposed) | View |
Page 477 of 20943, showing 5 records out of 104715 total, starting on record 2381, ending on 2385