CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
90890 | CVE-2016-4071 | Candidate | Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via format string specifiers in an SNMP::get call. | Assigned (20160423) | None (candidate not yet proposed) | View | |
25610 | CVE-2007-2253 | Candidate | Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol.php and (2) sdk/blanks/file_modules.php. | Assigned (20070425) | None (candidate not yet proposed) | View | |
91146 | CVE-2016-4327 | Candidate | Cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java/6.6 build SSJ-6.6-20090827-1616 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO. | Assigned (20160427) | None (candidate not yet proposed) | View | |
25866 | CVE-2007-2509 | Candidate | CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands. | Assigned (20070507) | None (candidate not yet proposed) | View | |
91402 | CVE-2016-4583 | Candidate | WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document. | Assigned (20160511) | None (candidate not yet proposed) | View |
Page 844 of 20943, showing 5 records out of 104715 total, starting on record 4216, ending on 4220