CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25352  CVE-2007-1995  Candidate  bgpd/bgp_attr.c in Quagga 0.98.6 and earlier, and 0.99.6 and earlier 0.99 versions, does not validate length values in the MP_REACH_NLRI and MP_UNREACH_NLRI attributes, which allows remote attackers to cause a denial of service (daemon crash or exit) via crafted UPDATE messages that trigger an assertion error or out of bounds read.  Assigned (20070411)  None (candidate not yet proposed)    View
90888  CVE-2016-4069  Candidate  Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail before 1.1.5 allows remote attackers to hijack the authentication of users for requests that download attachments and cause a denial of service (disk consumption) via unspecified vectors.  Assigned (20160423)  None (candidate not yet proposed)    View
25608  CVE-2007-2251  Candidate  Unspecified vulnerability in the Roles module in Xaraya 1.1.2 and earlier allows attackers to gain privileges via unspecified vectors, probably related to incorrect permission checking in xartemplates/user-view.xd.  Assigned (20070425)  None (candidate not yet proposed)    View
91144  CVE-2016-4325  Candidate  Lantronix xPrintServer devices with firmware before 5.0.1-65 have hardcoded credentials, which allows remote attackers to obtain root access via unspecified vectors.  Assigned (20160427)  None (candidate not yet proposed)    View
25864  CVE-2007-2507  Candidate  Directory traversal vulnerability in includes/download.php in Treble Designs 1024 CMS 0.7 allows remote attackers to read arbitrary files via a .. (dot dot) in the item parameter.  Assigned (20070503)  None (candidate not yet proposed)    View

Page 690 of 20943, showing 5 records out of 104715 total, starting on record 3446, ending on 3450

Actions