CVE List

Id CVE No. Status Description Phase Votes Comments Actions
81782  CVE-2015-4505  Candidate  updater.exe in Mozilla Firefox before 41.0 and Firefox ESR 38.x before 38.3 on Windows allows local users to write to arbitrary files by conducting a junction attack and waiting for an update operation by the Mozilla Maintenance Service.  Assigned (20150610)  None (candidate not yet proposed)    View
35256  CVE-2008-5139  Candidate  updatejail in jailer 0.4 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/#####.updatejail temporary file.  Assigned (20081118)  None (candidate not yet proposed)    View
64758  CVE-2013-4811  Candidate  UpdateDomainControllerServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the adCert argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.  Assigned (20130712)  None (candidate not yet proposed)    View
64759  CVE-2013-4812  Candidate  UpdateCertificatesServlet in the SNAC registration server in HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, and Identity Driven Manager (IDM) 4.0 does not properly validate the fileName argument, which allows remote attackers to upload .jsp files and consequently execute arbitrary code via unspecified vectors, aka ZDI-CAN-1743.  Assigned (20130712)  None (candidate not yet proposed)    View
90763  CVE-2016-3944  Candidate  UpdateAgent in Lenovo Accelerator Application allows man-in-the-middle attackers to execute arbitrary code by spoofing an update response from susapi.lenovomm.com.  Assigned (20160331)  None (candidate not yet proposed)    View

Page 814 of 20943, showing 5 records out of 104715 total, starting on record 4066, ending on 4070

Actions