CVE List

Id CVE No. Status Description Phase Votes Comments Actions
90890  CVE-2016-4071  Candidate  Format string vulnerability in the php_snmp_error function in ext/snmp/snmp.c in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via format string specifiers in an SNMP::get call.  Assigned (20160423)  None (candidate not yet proposed)    View
25610  CVE-2007-2253  Candidate  Exponent CMS 0.96.6 Alpha and earlier allows remote attackers to obtain path information via a direct request for (1) sdk/blanks/formcontrol.php and (2) sdk/blanks/file_modules.php.  Assigned (20070425)  None (candidate not yet proposed)    View
91146  CVE-2016-4327  Candidate  Cross-site scripting (XSS) vulnerability in WSO2 SOA Enablement Server for Java/6.6 build SSJ-6.6-20090827-1616 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.  Assigned (20160427)  None (candidate not yet proposed)    View
25866  CVE-2007-2509  Candidate  CRLF injection vulnerability in the ftp_putcmd function in PHP before 4.4.7, and 5.x before 5.2.2 allows remote attackers to inject arbitrary FTP commands via CRLF sequences in the parameters to earlier FTP commands.  Assigned (20070507)  None (candidate not yet proposed)    View
91402  CVE-2016-4583  Candidate  WebKit in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to bypass the Same Origin Policy and obtain image date from an unintended web site via a timing attack involving an SVG document.  Assigned (20160511)  None (candidate not yet proposed)    View

Page 844 of 20943, showing 5 records out of 104715 total, starting on record 4216, ending on 4220

Actions