CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36830  CVE-2008-6713  Candidate  World in Conflict (WIC) 1.008 and earlier allows remote attackers to cause a denial of service (access violation and crash) via a zero-byte data block to TCP port 48000, which triggers a NULL pointer dereference.  Assigned (20090410)  None (candidate not yet proposed)    View
35882  CVE-2008-5765  Candidate  WorkSimple 1.2.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing usernames and passwords via a direct request for data/usr.txt.  Assigned (20081230)  None (candidate not yet proposed)    View
6552  CVE-2002-2170  Candidate  Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP address of the local host, but does not provide additional authentication, which allows remote attackers to execute arbitrary code via a web page containing an HTTP POST request that accesses the dir.hts page on the localhost and adds an entire hard drive to be shared.  Assigned (20051116)  None (candidate not yet proposed)    View
7428  CVE-2003-0601  Candidate  Workgroup Manager in Apple Mac OS X Server 10.2 through 10.2.6 does not disable a password for a new account before it is saved for the first time, which allows remote attackers to gain unauthorized access via the new account before it is saved.  Assigned (20030723)  None (candidate not yet proposed)    View
4974  CVE-2002-0583  Candidate  WorkforceROI Xpede 4.1 uses a small random namespace (5 alphanumeric characters) for temporary expense claim reports in the /reports/temp directory, which allows remote attackers to read the reports via a brute force attack.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall    View

Page 141 of 20943, showing 5 records out of 104715 total, starting on record 701, ending on 705

Actions