CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
36880 | CVE-2008-6763 | Candidate | login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account"s username. | Assigned (20090428) | None (candidate not yet proposed) | View | |
102416 | CVE-2017-5596 | Candidate | In Wireshark 2.2.0 to 2.2.3 and 2.0.0 to 2.0.9, the ASTERIX dissector could go into an infinite loop, triggered by packet injection or a malformed capture file. This was addressed in epan/dissectors/packet-asterix.c by changing a data type to avoid an integer overflow. | Assigned (20170125) | None (candidate not yet proposed) | View | |
37136 | CVE-2008-7019 | Candidate | Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enombre and (2) euri cookies. | Assigned (20090821) | None (candidate not yet proposed) | View | |
102672 | CVE-2017-5852 | Candidate | The PoDoFo::PdfPage::GetInheritedKeyFromObject function in base/PdfVariant.cpp in PoDoFo 0.9.4 allows remote attackers to cause a denial of service (infinite loop) via a crafted file. | Assigned (20170201) | None (candidate not yet proposed) | View | |
37392 | CVE-2008-7275 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Open Ticket Request System (OTRS) before 2.3.3 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) AgentTicketMailbox or (2) CustomerTicketOverView. | Assigned (20110318) | None (candidate not yet proposed) | View |
Page 1329 of 20943, showing 5 records out of 104715 total, starting on record 6641, ending on 6645