CVE List

Id CVE No. Status Description Phase Votes Comments Actions
24072  CVE-2007-0715  Candidate  Heap-based buffer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PICT file.  Assigned (20070205)  None (candidate not yet proposed)    View
89608  CVE-2016-2789  Candidate  Cross-site scripting (XSS) vulnerability in the Web User Interface in Citrix XenMobile Server 10.0, 10.1 before Rolling Patch 4, and 10.3 before Rolling Patch 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20160301)  None (candidate not yet proposed)    View
24328  CVE-2007-0971  Candidate  Multiple SQL injection vulnerabilities in Jupiter CMS 1.1.5 allow remote attackers to execute arbitrary SQL commands via the Client-IP HTTP header and certain other HTTP headers, which set the ip variable that is used in SQL queries performed by index.php and certain other PHP scripts. NOTE: the attack vector might involve _SERVER.  Assigned (20070215)  None (candidate not yet proposed)    View
89864  CVE-2016-3045  Candidate  IBM Security Access Manager for Web stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referer header or browser history.  Assigned (20160309)  None (candidate not yet proposed)    View
24584  CVE-2007-1227  Candidate  VShieldCheck in McAfee VirusScan for Mac (Virex) before 7.7 patch 1 allow local users to change permissions of arbitrary files via a symlink attack on /Library/Application Support/Virex/VShieldExclude.txt, as demonstrated by symlinking to the root crontab file to execute arbitrary commands.  Assigned (20070302)  None (candidate not yet proposed)    View

Page 688 of 20943, showing 5 records out of 104715 total, starting on record 3436, ending on 3440

Actions