CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13539  CVE-2005-2333  Candidate  Cross-site scripting (XSS) vulnerability in smilies_popup.php in SEO-Board 1.0 allows remote attackers to inject arbitrary web script or HTML via the doc parameter.  Assigned (20050720)  None (candidate not yet proposed)    View
79075  CVE-2015-1798  Candidate  The symmetric-key feature in the receive function in ntp_proto.c in ntpd in NTP 4.x before 4.2.8p2 requires a correct MAC only if the MAC field has a nonzero length, which makes it easier for man-in-the-middle attackers to spoof packets by omitting the MAC.  Assigned (20150217)  None (candidate not yet proposed)    View
13795  CVE-2005-2589  Candidate  Unknown vulnerability in Linksys WRT54GS wireless router with firmware 4.50.6, with WPA Personal/TKIP authentication enabled, allows remote clients to bypass authentication by connecting without using encryption.  Assigned (20050817)  None (candidate not yet proposed)    View
79331  CVE-2015-2054  Candidate  CRLF injection vulnerability in export.cfg in the web-based administrative console for Sierra Wireless AirCard 760S, 762S, and 763S allows remote attackers to inject arbitrary headers via CRLF sequences in the save parameter.  Assigned (20150223)  None (candidate not yet proposed)    View
14051  CVE-2005-2845  Candidate  Ariba Spend Management System sends the username and password to the server in plaintext in a POST request, which allows remote attackers to obtain sensitive information.  Assigned (20050908)  None (candidate not yet proposed)    View

Page 18687 of 20943, showing 5 records out of 104715 total, starting on record 93431, ending on 93435

Actions