CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
12005 | CVE-2005-0799 | Candidate | MySQL 4.1.9, and possibly earlier versions, allows remote attackers with certain privileges to cause a denial of service (application crash) via a use command followed by an MS-DOS device name such as (1) LPT1 or (2) PRN. | Assigned (20050320) | None (candidate not yet proposed) | View | |
77541 | CVE-2015-0278 | Candidate | libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors. | Assigned (20141118) | None (candidate not yet proposed) | View | |
12261 | CVE-2005-1055 | Candidate | TowerBlog 0.6 and earlier stores the login data file under the web root, which allows remote attackers to obtain the MD5 checksums of the username and password via a direct request to the _dat/login file. | Assigned (20050412) | None (candidate not yet proposed) | View | |
77797 | CVE-2015-0534 | Candidate | EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x before 4.0.8 and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2, RSA BSAFE SSL-J before 6.2, and RSA BSAFE SSL-C 2.8.9 and earlier do not enforce certain constraints on certificate data, which allows remote attackers to defeat a fingerprint-based certificate-blacklist protection mechanism by including crafted data within a certificate"s unsigned portion, a similar issue to CVE-2014-8275. | Assigned (20141217) | None (candidate not yet proposed) | View | |
12517 | CVE-2005-1311 | Candidate | Cross-site scripting (XSS) vulnerability in Yappa-NG before 2.3.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | Assigned (20050427) | None (candidate not yet proposed) | View |
Page 18839 of 20943, showing 5 records out of 104715 total, starting on record 94191, ending on 94195