CVE List

Id CVE No. Status Description Phase Votes Comments Actions
30327  CVE-2008-0210  Candidate  Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting. NOTE: this can be leveraged to conduct directory traversal attacks without authentication by using CVE-2008-0140.  Assigned (20080109)  None (candidate not yet proposed)    View
40634  CVE-2009-3199  Candidate  Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes via a direct request for system_admin/admin.ucf.  Assigned (20090915)  None (candidate not yet proposed)    View
26528  CVE-2007-3171  Candidate  Uebimiau Webmail allows remote attackers to obtain sensitive information via a request to demo/pop3/error.php with an invalid value of the (1) smarty or (2) selected_theme parameter, which reveals the path in various error messages.  Assigned (20070611)  None (candidate not yet proposed)    View
21586  CVE-2006-5482  Candidate  ufs_vnops.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by calling the ftruncate function on a file type that is not VREG, VLNK or VDIR, which is not defined in POSIX.  Assigned (20061024)  None (candidate not yet proposed)    View
46799  CVE-2010-4215  Candidate  UI/Manage.pm in Foswiki 1.1.0 and 1.1.1 allows remote authenticated users to gain privileges by modifying the GROUP and ALLOWTOPICCHANGE preferences in the topic preferences for Main.AdminGroup.  Assigned (20101109)  None (candidate not yet proposed)    View

Page 18605 of 20943, showing 5 records out of 104715 total, starting on record 93021, ending on 93025

Actions