CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13589  CVE-2005-2383  Candidate  SQL injection vulnerability in auth.php in PHPNews 1.2.5 allows remote attackers to execute arbitrary SQL commands via the user parameter in an HTTP POST request.  Assigned (20050726)  None (candidate not yet proposed)    View
79125  CVE-2015-1848  Candidate  The pcs daemon (pcsd) in PCS 0.9.137 and earlier does not set the secure flag for a cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2015-3983 is for the issue with not setting the HTTPOnly flag.  Assigned (20150217)  None (candidate not yet proposed)    View
13845  CVE-2005-2639  Candidate  Buffer overflow in Chris Moneymaker"s World Poker Championship 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long nickname.  Assigned (20050820)  None (candidate not yet proposed)    View
79381  CVE-2015-2104  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20150227)  None (candidate not yet proposed)    View
14101  CVE-2005-2895  Candidate  setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attackers to obtain sensitive information via a %00 (a null byte) in the u parameter, which reveals the path in an error message.  Assigned (20050914)  None (candidate not yet proposed)    View

Page 1671 of 20943, showing 5 records out of 104715 total, starting on record 8351, ending on 8355

Actions