CVE List

Id CVE No. Status Description Phase Votes Comments Actions
30474  CVE-2008-0357  Candidate  Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.  Assigned (20080118)  None (candidate not yet proposed)    View
96010  CVE-2016-9190  Candidate  Pillow before 3.3.2 allows context-dependent attackers to execute arbitrary code by using the "crafted image file" approach, related to an "Insecure Sign Extension" issue affecting the ImagingNew in Storage.c component.  Assigned (20161104)  None (candidate not yet proposed)    View
30730  CVE-2008-0613  Candidate  Open redirect vulnerability in htdocs/user.php in XOOPS 2.0.18 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the xoops_redirect parameter.  Assigned (20080205)  None (candidate not yet proposed)    View
96266  CVE-2016-9446  Candidate  The vmnc decoder in the gstreamer does not initialize the render canvas, which allows remote attackers to obtain sensitive information as demonstrated by thumbnailing a simple 1 frame vmnc movie that does not draw to the allocated render canvas.  Assigned (20161118)  None (candidate not yet proposed)    View
30986  CVE-2008-0869  Candidate  Cross-site scripting (XSS) vulnerability in BEA WebLogic Workshop 8.1 through SP6 and Workshop for WebLogic 9.0 through 10.0 allows remote attackers to inject arbitrary web script or HTML via a "framework defined request parameter" when using WebLogic Workshop or Apache Beehive NetUI framework with page flows.  Assigned (20080220)  None (candidate not yet proposed)    View

Page 853 of 20943, showing 5 records out of 104715 total, starting on record 4261, ending on 4265

Actions