CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
30471 | CVE-2008-0354 | Candidate | Cross-site scripting (XSS) vulnerability in the chat client in IBM Lotus Sametime 7.5 and 7.5.1 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted message, which triggers code execution after a mouseover event initiated by the victim. | Assigned (20080118) | None (candidate not yet proposed) | View | |
96007 | CVE-2016-9187 | Candidate | Unrestricted file upload vulnerability in the double extension support in the "image" module in Moodle 3.1.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, and then accessing it via unspecified vectors. | Assigned (20161104) | None (candidate not yet proposed) | View | |
30727 | CVE-2008-0610 | Candidate | Stack-based buffer overflow in the ClientConnection::NegotiateProtocolVersion function in vncviewer/ClientConnection.cpp in vncviewer for UltraVNC 1.0.2 and 1.0.4 before 01252008, when in LISTENING mode or when using the DSM plugin, allows remote attackers to execute arbitrary code or cause a denial of service (crash) via a modified size value. | Assigned (20080205) | None (candidate not yet proposed) | View | |
96263 | CVE-2016-9443 | Candidate | An issue was discovered in the Tatsuya Kinoshita w3m fork before 0.5.3-31. w3m allows remote attackers to cause a denial of service (segmentation fault and crash) via a crafted HTML page. | Assigned (20161118) | None (candidate not yet proposed) | View | |
30983 | CVE-2008-0866 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in BEA WebLogic Workshop allow remote attackers to inject arbitrary web script or HTML via an invalid action URI, which is not properly handled by NetUI page flows. | Assigned (20080220) | None (candidate not yet proposed) | View |
Page 606 of 20943, showing 5 records out of 104715 total, starting on record 3026, ending on 3030