CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
29960 | CVE-2007-6603 | Candidate | Hot or Not Clone has insufficient access control for producing and reading database backups, which allows remote attackers to obtain the administrator username and password via a direct request to control/backup/backup.php, which generates a backup/dump/backup.sql file that can be downloaded via a direct request to control/downloadfile.php. | Assigned (20071231) | None (candidate not yet proposed) | View | |
95496 | CVE-2016-8676 | Candidate | The get_vlc2 function in get_bits.h in Libav 11.9 allows remote attackers to cause a denial of service (NULL pointer dereference and crash) via a crafted mp3 file. NOTE: this issue exists due to an incomplete fix for CVE-2016-8675. | Assigned (20161015) | None (candidate not yet proposed) | View | |
30216 | CVE-2008-0099 | Candidate | Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL commands via the searchtext parameter to search.php, and unspecified other vectors. | Assigned (20080107) | None (candidate not yet proposed) | View | |
95752 | CVE-2016-8932 | Candidate | IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server. | Assigned (20161025) | None (candidate not yet proposed) | View | |
30472 | CVE-2008-0355 | Candidate | SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote attackers to execute arbitrary SQL commands via the id parameter in a section action, a different vector than CVE-2007-2866. | Assigned (20080118) | None (candidate not yet proposed) | View |
Page 685 of 20943, showing 5 records out of 104715 total, starting on record 3421, ending on 3425