CVE List

Id CVE No. Status Description Phase Votes Comments Actions
31251  CVE-2008-1134  Candidate  OMEGA (aka Omegasoft) INterneSErvicesLosungen (INSEL) 7 supports authentication with a cookie that lacks a shared secret, which allows remote attackers to login as an arbitrary user via a modified cookie.  Assigned (20080304)  None (candidate not yet proposed)    View
96787  CVE-2016-9967  Candidate  Lack of appropriate exception handling in some receivers of the Telecom application on Samsung Note devices with L(5.0/5.1), M(6.0), and N(7.0) software allows attackers to crash the system easily resulting in a possible DoS attack, or possibly gain privileges. The Samsung ID is SVE-2016-7121.  Assigned (20161216)  None (candidate not yet proposed)    View
31507  CVE-2008-1390  Candidate  The AsteriskGUI HTTP server in Asterisk Open Source 1.4.x before 1.4.19-rc3 and 1.6.x before 1.6.0-beta6, Business Edition C.x.x before C.1.6, AsteriskNOW before 1.0.2, Appliance Developer Kit before revision 104704, and s800i 1.0.x before 1.1.0.2 generates insufficiently random manager ID values, which makes it easier for remote attackers to hijack a manager session via a series of ID guesses.  Assigned (20080318)  None (candidate not yet proposed)    View
97043  CVE-2017-0224  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160909)  None (candidate not yet proposed)    View
31763  CVE-2008-1646  Candidate  SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the dl_id parameter.  Assigned (20080402)  None (candidate not yet proposed)    View

Page 1558 of 20943, showing 5 records out of 104715 total, starting on record 7786, ending on 7790

Actions