CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87048  CVE-2016-0752  Candidate  Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.x before 4.2.5.1, and 5.x before 5.0.0.beta1.1 allows remote attackers to read arbitrary files by leveraging an application"s unrestricted use of the render method and providing a .. (dot dot) in a pathname.  Assigned (20151216)  None (candidate not yet proposed)    View
21768  CVE-2006-5664  Candidate  The installation script in IBM Informix Dynamic Server 10.00, Informix Client Software Development Kit (CSDK) 2.90, and Informix I-Connect 2.90 allows local users to "compromise security" via a symlink attack on temporary files.  Assigned (20061102)  None (candidate not yet proposed)    View
87304  CVE-2016-1000006  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160705)  None (candidate not yet proposed)    View
22024  CVE-2006-5920  Candidate  ** DISPUTED ** PHP remote file inclusion vulnerability in common.php in Yuuki Yoshizawa Exporia 0.3.0 allows remote attackers to execute arbitrary PHP code via a URL in the lan parameter. NOTE: SecurityFocus disputes this issue, saying "further analysis reveals that the application is not vulnerable." NOTE: this issue may overlap CVE-2006-5113.  Assigned (20061115)  None (candidate not yet proposed)    View
87560  CVE-2016-10063  Candidate  Buffer overflow in coders/tiff.c in ImageMagick before 6.9.5-1 allows remote attackers to cause a denial of service (application crash) or have other unspecified impact via a crafted file, related to extend validity.  Assigned (20161226)  None (candidate not yet proposed)    View

Page 672 of 20943, showing 5 records out of 104715 total, starting on record 3356, ending on 3360

Actions