CVE List

Id CVE No. Status Description Phase Votes Comments Actions
88803  CVE-2016-1984  Candidate  The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerability than CVE-2015-8362.  Assigned (20160121)  None (candidate not yet proposed)    View
23523  CVE-2007-0166  Candidate  The jail rc.d script in FreeBSD 5.3 up to 6.2 does not verify pathnames when writing to /var/log/console.log during a jail start-up, or when file systems are mounted or unmounted, which allows local root users to overwrite arbitrary files, or mount/unmount files, outside of the jail via a symlink attack.  Assigned (20070109)  None (candidate not yet proposed)    View
89059  CVE-2016-2240  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20160207)  None (candidate not yet proposed)    View
23779  CVE-2007-0422  Candidate  BEA WebLogic Server 9.0, 9.1, and 9.2 Gold, when running on Solaris 9, allows remote attackers to cause a denial of service (server inaccessibility) via manipulated socket connections.  Assigned (20070122)  None (candidate not yet proposed)    View
89315  CVE-2016-2496  Candidate  The Framework UI permission-dialog implementation in Android 6.x before 2016-06-01 allows attackers to conduct tapjacking attacks and access arbitrary private-storage files by creating a partially overlapping window, aka internal bug 26677796.  Assigned (20160218)  None (candidate not yet proposed)    View

Page 18653 of 20943, showing 5 records out of 104715 total, starting on record 93261, ending on 93265

Actions