CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
30327 | CVE-2008-0210 | Candidate | Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting. NOTE: this can be leveraged to conduct directory traversal attacks without authentication by using CVE-2008-0140. | Assigned (20080109) | None (candidate not yet proposed) | View | |
40634 | CVE-2009-3199 | Candidate | Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes via a direct request for system_admin/admin.ucf. | Assigned (20090915) | None (candidate not yet proposed) | View | |
26528 | CVE-2007-3171 | Candidate | Uebimiau Webmail allows remote attackers to obtain sensitive information via a request to demo/pop3/error.php with an invalid value of the (1) smarty or (2) selected_theme parameter, which reveals the path in various error messages. | Assigned (20070611) | None (candidate not yet proposed) | View | |
21586 | CVE-2006-5482 | Candidate | ufs_vnops.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by calling the ftruncate function on a file type that is not VREG, VLNK or VDIR, which is not defined in POSIX. | Assigned (20061024) | None (candidate not yet proposed) | View | |
46799 | CVE-2010-4215 | Candidate | UI/Manage.pm in Foswiki 1.1.0 and 1.1.1 allows remote authenticated users to gain privileges by modifying the GROUP and ALLOWTOPICCHANGE preferences in the topic preferences for Main.AdminGroup. | Assigned (20101109) | None (candidate not yet proposed) | View |
Page 18605 of 20943, showing 5 records out of 104715 total, starting on record 93021, ending on 93025