CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25089  CVE-2007-1732  Candidate  ** DISPUTED ** Cross-site scripting (XSS) vulnerability in an mt import in wp-admin/admin.php in WordPress 2.1.2 allows remote authenticated administrators to inject arbitrary web script or HTML via the demo parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: another researcher disputes this issue, stating that this is legitimate functionality for administrators. However, it has been patched by at least one vendor.  Assigned (20070328)  None (candidate not yet proposed)    View
90625  CVE-2016-3806  Candidate  The MediaTek display driver in Android before 2016-07-05 on Android One devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28402341 and MediaTek internal bug ALPS02715341.  Assigned (20160330)  None (candidate not yet proposed)    View
25345  CVE-2007-1988  Candidate  Cross-site scripting (XSS) vulnerability in kernel/filters.inc.php in PHPEcho CMS 2.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.  Assigned (20070411)  None (candidate not yet proposed)    View
90881  CVE-2016-4062  Candidate  Foxit Reader and PhantomPDF before 7.3.4 on Windows improperly report format errors recursively, which allows remote attackers to cause a denial of service (application hang) via a crafted PDF.  Assigned (20160422)  None (candidate not yet proposed)    View
25601  CVE-2007-2244  Candidate  Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) BMP, (2) DIB, or (3) RLE file.  Assigned (20070425)  None (candidate not yet proposed)    View

Page 728 of 20943, showing 5 records out of 104715 total, starting on record 3636, ending on 3640

Actions