CVE List

Id CVE No. Status Description Phase Votes Comments Actions
36887  CVE-2008-6770  Candidate  YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to a database containing user credentials via a direct request for users.txt.  Assigned (20090429)  None (candidate not yet proposed)    View
102423  CVE-2017-5603  Candidate  An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application"s display. This allows for various kinds of social engineering attacks. This CVE is for Jitsi 2.5.5061 - 2.9.5544.  Assigned (20170128)  None (candidate not yet proposed)    View
37143  CVE-2008-7026  Candidate  Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an executable extension as an avatar, then accessing it via a direct request to the file in (1) student/avatars/ or (2) professor/avatars/.  Assigned (20090821)  None (candidate not yet proposed)    View
102679  CVE-2017-5859  Candidate  On Cambium Networks cnPilot R200/201 devices before 4.3, there is a vulnerability involving the certificate of the device and its RSA keys, aka RBN-183.  Assigned (20170202)  None (candidate not yet proposed)    View
37399  CVE-2008-7282  Candidate  Kernel/Output/HTML/CustomerNewTicketQueueSelectionGeneric.pm in Open Ticket Request System (OTRS) before 2.2.6, when the CustomerPanelOwnSelection and CustomerGroupSupport options are enabled, allows remote authenticated users to bypass intended access restrictions, and perform certain (1) list and (2) write operations on queues, via unspecified vectors.  Assigned (20110318)  None (candidate not yet proposed)    View

Page 1885 of 20943, showing 5 records out of 104715 total, starting on record 9421, ending on 9425

Actions