CVE List

Id CVE No. Status Description Phase Votes Comments Actions
25090  CVE-2007-1733  Candidate  Buffer overflow in InterVations NaviCOPA HTTP Server 2.01 allows remote attackers to execute arbitrary code via a long (1) /cgi-bin/ or (2) /cgi/ pathname in an HTTP GET request, probably a different issue than CVE-2006-5112.  Assigned (20070328)  None (candidate not yet proposed)    View
90626  CVE-2016-3807  Candidate  The serial peripheral interface driver in Android before 2016-07-05 on Nexus 5X and 6P devices allows attackers to gain privileges via a crafted application, aka internal bug 28402196.  Assigned (20160330)  None (candidate not yet proposed)    View
25346  CVE-2007-1989  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in DotClear before 1.2.6 allow remote attackers to inject arbitrary web script or HTML via the (1) post_id parameter to ecrire/trackback.php or the (2) tool_url parameter to tools/thememng/index.php. NOTE: some of these details are obtained from third party information.  Assigned (20070411)  None (candidate not yet proposed)    View
90882  CVE-2016-4063  Candidate  Use-after-free vulnerability in Foxit Reader and PhantomPDF before 7.3.4 on Windows allows remote attackers to execute arbitrary code via an object with a revision number of -1 in a PDF document.  Assigned (20160422)  None (candidate not yet proposed)    View
25602  CVE-2007-2245  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin before 2.10.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the fieldkey parameter to browse_foreigners.php or (2) certain input to the PMA_sanitize function.  Assigned (20070425)  None (candidate not yet proposed)    View

Page 808 of 20943, showing 5 records out of 104715 total, starting on record 4036, ending on 4040

Actions