CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
88496 | CVE-2016-1677 | Candidate | uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion." | Assigned (20160112) | None (candidate not yet proposed) | View | |
14070 | CVE-2005-2864 | Candidate | URBAN 1.5.3_1 allows local users to overwrite arbitrary files via a symlink attack on the (1) high score or (2) save game files. | Assigned (20050908) | None (candidate not yet proposed) | View | |
42020 | CVE-2009-4585 | Candidate | UranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/db.mdb. | Assigned (20100106) | None (candidate not yet proposed) | View | |
35510 | CVE-2008-5393 | Candidate | UPR-Kernel in Ubuntu Privacy Remix (UPR) before 8.04_r1 includes kernel support for mounting RAID arrays, which might allow remote attackers to bypass intended isolation mechanisms by (1) reading from or (2) writing to these arrays. | Assigned (20081208) | None (candidate not yet proposed) | View | |
70712 | CVE-2014-3416 | Candidate | uPortal before 4.0.13.1 does not properly check the MANAGE permissions, which allows remote authenticated users to manage arbitrary portlets by leveraging the SUBSCRIBE permission for the portlet-admin portlet. | Assigned (20140507) | None (candidate not yet proposed) | View |
Page 809 of 20943, showing 5 records out of 104715 total, starting on record 4041, ending on 4045