CVE List

Id CVE No. Status Description Phase Votes Comments Actions
88496  CVE-2016-1677  Candidate  uri.js in Google V8 before 5.1.281.26, as used in Google Chrome before 51.0.2704.63, uses an incorrect array type, which allows remote attackers to obtain sensitive information by calling the decodeURI function and leveraging "type confusion."  Assigned (20160112)  None (candidate not yet proposed)    View
14070  CVE-2005-2864  Candidate  URBAN 1.5.3_1 allows local users to overwrite arbitrary files via a symlink attack on the (1) high score or (2) save game files.  Assigned (20050908)  None (candidate not yet proposed)    View
42020  CVE-2009-4585  Candidate  UranyumSoft Listing Service stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/db.mdb.  Assigned (20100106)  None (candidate not yet proposed)    View
35510  CVE-2008-5393  Candidate  UPR-Kernel in Ubuntu Privacy Remix (UPR) before 8.04_r1 includes kernel support for mounting RAID arrays, which might allow remote attackers to bypass intended isolation mechanisms by (1) reading from or (2) writing to these arrays.  Assigned (20081208)  None (candidate not yet proposed)    View
70712  CVE-2014-3416  Candidate  uPortal before 4.0.13.1 does not properly check the MANAGE permissions, which allows remote authenticated users to manage arbitrary portlets by leveraging the SUBSCRIBE permission for the portlet-admin portlet.  Assigned (20140507)  None (candidate not yet proposed)    View

Page 809 of 20943, showing 5 records out of 104715 total, starting on record 4041, ending on 4045

Actions