CVE List

Id CVE No. Status Description Phase Votes Comments Actions
23562  CVE-2007-0205  Candidate  Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to create files in arbitrary directories via ".." sequences in the (1) aj_skin and (2) skin_edit parameters. NOTE: this can be leveraged for file inclusion by creating a skin file in the lang directory, then referencing that file via the lang parameter to index.php, which passes a sanity check in livre_include.php.  Assigned (20070111)  None (candidate not yet proposed)    View
89098  CVE-2016-2279  Candidate  Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20160209)  None (candidate not yet proposed)    View
23818  CVE-2007-0461  Candidate  Multiple memory leaks in the Dazuko anti-virus helper module before 2.3.2 allow attackers to cause a denial of service (memory consumption) via unknown vectors.  Assigned (20070123)  None (candidate not yet proposed)    View
89354  CVE-2016-2535  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160222)  None (candidate not yet proposed)    View
24074  CVE-2007-0717  Candidate  Integer overflow in Apple QuickTime before 7.1.5 allows remote user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted QTIF file.  Assigned (20070205)  None (candidate not yet proposed)    View

Page 834 of 20943, showing 5 records out of 104715 total, starting on record 4166, ending on 4170

Actions