CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
90891 | CVE-2016-4072 | Candidate | The Phar extension in PHP before 5.5.34, 5.6.x before 5.6.20, and 7.x before 7.0.5 allows remote attackers to execute arbitrary code via a crafted filename, as demonstrated by mishandling of characters by the phar_analyze_path function in ext/phar/phar.c. | Assigned (20160423) | None (candidate not yet proposed) | View | |
25611 | CVE-2007-2254 | Candidate | PHP remote file inclusion vulnerability in admin/setup/level2.php in PHP Classifieds 6.04, and probably earlier versions, allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter. NOTE: this product was referred to as "Allfaclassfieds" in the original disclosure. | Assigned (20070425) | None (candidate not yet proposed) | View | |
91147 | CVE-2016-4328 | Candidate | MEDHOST Perioperative Information Management System (aka PIMS or VPIMS) before 2015R1 has hardcoded credentials, which makes it easier for remote attackers to obtain sensitive information via direct requests to the application database server. | Assigned (20160427) | None (candidate not yet proposed) | View | |
25867 | CVE-2007-2510 | Candidate | Buffer overflow in the make_http_soap_request function in PHP before 5.2.2 has unknown impact and remote attack vectors, possibly related to "/" (slash) characters. | Assigned (20070507) | None (candidate not yet proposed) | View | |
91403 | CVE-2016-4584 | Candidate | The WebKit Page Loading implementation in Apple iOS before 9.3.3, Safari before 9.1.2, and tvOS before 9.2.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site. | Assigned (20160511) | None (candidate not yet proposed) | View |
Page 916 of 20943, showing 5 records out of 104715 total, starting on record 4576, ending on 4580