CVE List

Id CVE No. Status Description Phase Votes Comments Actions
26631  CVE-2007-3274  Candidate  Apple Safari 3.0 and 3.0.1 on Windows XP SP2 allows attackers to cause a denial of service (application crash) via JavaScript that sets the document.location variable, as demonstrated by an empty value of document.location.  Assigned (20070619)  None (candidate not yet proposed)    View
92167  CVE-2016-5348  Candidate  The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 before 2016-10-01 allows man-in-the-middle attackers to cause a denial of service (memory consumption, and device hang or reboot) via a large xtra.bin or xtra2.bin file on a spoofed Qualcomm gpsonextra.net or izatcloud.net host, aka internal bug 29555864.  Assigned (20160609)  None (candidate not yet proposed)    View
26887  CVE-2007-3530  Candidate  PHPDirector 0.21 and earlier stores the admin account name and password in config.php, which allows local users to gain privileges by reading this file.  Assigned (20070703)  None (candidate not yet proposed)    View
92423  CVE-2016-5604  Candidate  Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Enterprise Manager Grid Control 12.1.0.5 allows local users to affect confidentiality and integrity via vectors related to Security Framework, a different vulnerability than CVE-2016-3563.  Assigned (20160616)  None (candidate not yet proposed)    View
27143  CVE-2007-3786  Candidate  ** DISPUTED ** Cross-site request forgery (CSRF) vulnerability on the eSoft InstaGate EX2 UTM device before firmware 3.1.20070615 allows remote attackers to perform privileged actions as administrators. NOTE: the vendor disputes the distribution of the vulnerable software, stating that it was a custom build for a former customer.  Assigned (20070715)  None (candidate not yet proposed)    View

Page 600 of 20943, showing 5 records out of 104715 total, starting on record 2996, ending on 3000

Actions