CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13539 | CVE-2005-2333 | Candidate | Cross-site scripting (XSS) vulnerability in smilies_popup.php in SEO-Board 1.0 allows remote attackers to inject arbitrary web script or HTML via the doc parameter. | Assigned (20050720) | None (candidate not yet proposed) | View | |
79075 | CVE-2015-1798 | Candidate | The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p2 requires a correct MAC only if the MAC field has a nonzero length, which makes it easier for man-in-the-middle attackers to spoof packets by omitting the MAC. | Assigned (20150217) | None (candidate not yet proposed) | View | |
13795 | CVE-2005-2589 | Candidate | Unknown vulnerability in Linksys WRT54GS wireless router with firmware 4.50.6, with WPA Personal/TKIP authentication enabled, allows remote clients to bypass authentication by connecting without using encryption. | Assigned (20050817) | None (candidate not yet proposed) | View | |
79331 | CVE-2015-2054 | Candidate | CRLF injection vulnerability in export.cfg in the web-based administrative console for Sierra Wireless AirCard 760S, 762S, and 763S allows remote attackers to inject arbitrary headers via CRLF sequences in the save parameter. | Assigned (20150223) | None (candidate not yet proposed) | View | |
14051 | CVE-2005-2845 | Candidate | Ariba Spend Management System sends the username and password to the server in plaintext in a POST request, which allows remote attackers to obtain sensitive information. | Assigned (20050908) | None (candidate not yet proposed) | View |
Page 18687 of 20943, showing 5 records out of 104715 total, starting on record 93431, ending on 93435