CVE List

Id CVE No. Status Description Phase Votes Comments Actions
30209  CVE-2008-0092  Candidate  Cross-site scripting (XSS) vulnerability in index.php in the search module in Appalachian State University phpWebSite 1.4.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.  Assigned (20080103)  None (candidate not yet proposed)    View
95745  CVE-2016-8925  Candidate  IBM Tivoli Application Dependency Discovery Manager 7.2.2 and 7.3 could allow a remote attacker to include arbitrary files which could allow the attacker to read any file on the system. IBM X-Force ID: 118538.  Assigned (20161025)  None (candidate not yet proposed)    View
30465  CVE-2008-0348  Candidate  Multiple unspecified vulnerabilities in the PeopleTools component in Oracle PeopleSoft Enterprise and JD Edwards EnterpriseOne 8.22.18, 8.48.15, and 8.49.07 have unknown impact and remote attack vectors, aka (1) PSE01, (2) PSE03, and (3) PSE04.  Assigned (20080117)  None (candidate not yet proposed)    View
96001  CVE-2016-9181  Candidate  perl-Image-Info: When parsing an SVG file, external entity expansion (XXE) was not disabled. An attacker could craft an SVG file which, when processed by an application using perl-Image-Info, could cause denial of service or, potentially, information disclosure.  Assigned (20161104)  None (candidate not yet proposed)    View
30721  CVE-2008-0604  Candidate  The LDAP authentication feature in XLight FTP Server before 2.83, when used with some unspecified LDAP servers, does not check for blank passwords, which allows remote attackers to bypass intended access restrictions.  Assigned (20080205)  None (candidate not yet proposed)    View

Page 736 of 20943, showing 5 records out of 104715 total, starting on record 3676, ending on 3680

Actions