NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
31837  CVE-2014-3686  wpa_supplicant and hostapd 0.7.2 through 2.2, when running with certain configurations and using wpa_cli or hostapd_cli with action scripts, allows remote attackers to execute arbitrary commands via a crafted frame.    6.8  Medium  2017-01-19  2016-07-26  View
20113  CVE-2016-4477  wpa_supplicant 0.4.0 through 2.5 does not reject and characters in passphrase parameters, which allows local users to trigger arbitrary library loading and consequently gain privileges, or cause a denial of service (daemon outage), via a crafted (1) SET, (2) SET_CRED, or (3) SET_NETWORK command.    4.4  Medium  2017-01-19  2016-05-10  View
52462  CVE-2007-0233  wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric parameter with a value matching an alphanumeric parameter"s hash value, which allows remote attackers to execute arbitrary SQL commands via the tb_id parameter. NOTE: it could be argued that this vulnerability is due to a bug in the unset PHP command (CVE-2006-3017) and the proper fix should be in PHP; if so, then this should not be treated as a vulnerability in WordPress.    7.5  High  2017-01-07  2011-03-07  View
50074  CVE-2009-2852  WP-Syntax plugin 0.9.1 and earlier for Wordpress, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via the test_filter[wp_head] array parameter to test/index.php, which is used in a call to the call_user_func_array function.    6.8  Medium  2017-01-07  2009-09-04  View
37015  CVE-2013-0721  wp-php-widget.php in the WP PHP widget plugin 1.0.2 for WordPress allows remote attackers to obtain sensitive information via a direct request, which reveals the full path in an error message.    Medium  2017-01-18  2013-01-08  View

Page 151 of 17672, showing 5 records out of 88360 total, starting on record 751, ending on 755

Actions