CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36880  CVE-2008-6763  Candidate  login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account"s username.  Assigned (20090428)  None (candidate not yet proposed)    View
102416  CVE-2017-5596  Candidate  In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the ASTERIX dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-asterix.c by changing a data type to avoid an integer overflow.  Assigned (20170125)  None (candidate not yet proposed)    View
37136  CVE-2008-7019  Candidate  Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enombre and (2) euri cookies.  Assigned (20090821)  None (candidate not yet proposed)    View
102672  CVE-2017-5852  Candidate  The PoDoFo::PdfPage::GetInheritedKeyFromObject function in base/PdfVariant.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted file.  Assigned (20170201)  None (candidate not yet proposed)    View
37392  CVE-2008-7275  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) before 2.3.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) AgentTicketMailbox or (2) CustomerTicketOverView.  Assigned (20110318)  None (candidate not yet proposed)    View

Page 1329 of 20943, showing 5 records out of 104715 total, starting on record 6641, ending on 6645

Actions