CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23816  CVE-2007-0459  Candidate  packet-tcp.c in the TCP dissector in Wireshark (formerly Ethereal) 0.99.2 through 0.99.4 allows remote attackers to cause a denial of service (application crash or hang) via fragmented HTTP packets.  Assigned (20070123)  None (candidate not yet proposed)    View
89352  CVE-2016-2533  Candidate  Buffer overflow in the ImagingPcdDecode function in PcdDecode.c in Pillow before 3.1.1 and Python Imaging Library (PIL) 1.1.7 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PhotoCD file.  Assigned (20160222)  None (candidate not yet proposed)    View
24072  CVE-2007-0715  Candidate  Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT file.  Assigned (20070205)  None (candidate not yet proposed)    View
89608  CVE-2016-2789  Candidate  Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20160301)  None (candidate not yet proposed)    View
24328  CVE-2007-0971  Candidate  Multiple SQL injection vulnerabilities in Jupiter CMS 1.1.5 allow remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header and certain other HTTP headers, which set the ip variable that is used in SQL queries performed by index.php and certain other PHP scripts. NOTE: the attack vector might involve _SERVER.  Assigned (20070215)  None (candidate not yet proposed)    View

Page 681 of 20943, showing 5 records out of 104715 total, starting on record 3401, ending on 3405

Actions