CVE List

Id CVE No. Status Description Phase Votes Comments Actions
12005  CVE-2005-0799  Candidate  MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause a denial of service (application crash) via a use command followed by an MS-DOS device name such as (1) LPT1 or (2) PRN.  Assigned (20050320)  None (candidate not yet proposed)    View
77541  CVE-2015-0278  Candidate  libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.  Assigned (20141118)  None (candidate not yet proposed)    View
12261  CVE-2005-1055  Candidate  TowerBlog 0.6 and earlier stores the login data file under the web root, which allows remote attackers to obtain the MD5 checksums of the username and password via a direct request to the _dat/login file.  Assigned (20050412)  None (candidate not yet proposed)    View
77797  CVE-2015-0534  Candidate  EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2, RSA BSAFE SSL-J before 6.2, and RSA BSAFE SSL-C 2.8.9 and earlier do not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate"s unsigned portion, a similar issue to CVE-2014-8275.  Assigned (20141217)  None (candidate not yet proposed)    View
12517  CVE-2005-1311  Candidate  Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors.  Assigned (20050427)  None (candidate not yet proposed)    View

Page 18839 of 20943, showing 5 records out of 104715 total, starting on record 94191, ending on 94195

Actions