CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25353  CVE-2007-1996  Candidate  PHP remote file inclusion vulnerability in codebreak.php in CodeBreak, probably 1.1.2 and earlier, allows remote attackers to execute arbitrary PHP code via a URL in the process_method parameter.  Assigned (20070411)  None (candidate not yet proposed)    View
90889  CVE-2016-4070  Candidate  ** DISPUTED ** Integer overflow in the php_raw_url_encode function in ext/standard/url.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to cause a denial of service (application crash) via a long string to the rawurlencode function. NOTE: the vendor says "Not sure if this qualifies as security issue (probably not)."  Assigned (20160423)  None (candidate not yet proposed)    View
25609  CVE-2007-2252  Candidate  Directory traversal vulnerability in iconspopup.php in Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain sensitive information via a .. (dot dot) in the icodir parameter.  Assigned (20070425)  None (candidate not yet proposed)    View
91145  CVE-2016-4326  Candidate  The Chef Manage (formerly opscode-manage) add-on before 1.12.0 for Chef allows remote attackers to execute arbitrary code via crafted serialized data in a cookie.  Assigned (20160427)  None (candidate not yet proposed)    View
25865  CVE-2007-2508  Candidate  Multiple stack-based buffer overflows in Trend Micro ServerProtect 5.58 before Security Patch 2 Build 1174 allow remote attackers to execute arbitrary code via crafted data to (1) TCP port 5168, which triggers an overflow in the CAgRpcClient::CreateBinding function in the AgRpcCln.dll library in SpntSvc.exe; or (2) TCP port 3628, which triggers an overflow in EarthAgent.exe. NOTE: both issues are reachable via TmRpcSrv.dll.  Assigned (20070507)  None (candidate not yet proposed)    View

Page 767 of 20943, showing 5 records out of 104715 total, starting on record 3831, ending on 3835

Actions