CVE List

Id CVE No. Status Description Phase Votes Comments Actions
2292  CVE-2000-0716  Entry  WorldClient email client in MDaemon 2.8 includes the session ID in the referer field of an HTTP request when the user clicks on a URL, which allows the visited web site to hijack the session ID and read the user"s email.        View
67828  CVE-2014-0419  Candidate  Unspecified vulnerability in the Oracle Secure Global Desktop (SGD) component in Oracle Virtualization SGD before 4.63 with December 2013 PSU, 4.71, 5.0 with December 2013 PSU, and 5.10 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Administration Console and Workspace Web Applications.  Assigned (20131212)  None (candidate not yet proposed)    View
2548  CVE-2000-0979  Entry  File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file share, which allows remote attackers to bypass share access controls by sending a 1-byte password that matches the first character of the real password, aka the "Share Level Password" vulnerability.        View
68084  CVE-2014-0675  Candidate  The Expressway component in Cisco TelePresence Video Communication Server (VCS) uses the same default X.509 certificate across different customers" installations, which makes it easier for remote attackers to conduct man-in-the-middle attacks against SSL sessions by leveraging the certificate"s trust relationship, aka Bug ID CSCue07471.  Assigned (20140102)  None (candidate not yet proposed)    View
2804  CVE-2000-1237  Candidate  The POP3 server in FTGate returns an -ERR code after receiving an invalid USER request, which makes it easier for remote attackers to determine valid usernames and conduct brute force password guessing.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 19614 of 20943, showing 5 records out of 104715 total, starting on record 98066, ending on 98070

Actions