CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
24072 | CVE-2007-0715 | Candidate | Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT file. | Assigned (20070205) | None (candidate not yet proposed) | View | |
89608 | CVE-2016-2789 | Candidate | Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20160301) | None (candidate not yet proposed) | View | |
24328 | CVE-2007-0971 | Candidate | Multiple SQL injection vulnerabilities in Jupiter CMS 1.1.5 allow remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header and certain other HTTP headers, which set the ip variable that is used in SQL queries performed by index.php and certain other PHP scripts. NOTE: the attack vector might involve _SERVER. | Assigned (20070215) | None (candidate not yet proposed) | View | |
89864 | CVE-2016-3045 | Candidate | IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history. | Assigned (20160309) | None (candidate not yet proposed) | View | |
24584 | CVE-2007-1227 | Candidate | VShieldCheck in McAfee VirusScan for Mac (Virex) before 7.7 patch 1 allow local users to change permissions of arbitrary files via a symlink attack on /Library/Application Support/Virex/VShieldExclude.txt, as demonstrated by symlinking to the root crontab file to execute arbitrary commands. | Assigned (20070302) | None (candidate not yet proposed) | View |
Page 688 of 20943, showing 5 records out of 104715 total, starting on record 3436, ending on 3440