CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13299  CVE-2005-2093  Candidate  Oracle 9i Application Server (Oracle9iAS) 9.0.2 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Application Server to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling."  Assigned (20050630)  None (candidate not yet proposed)    View
78835  CVE-2015-1558  Candidate  Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs.  Assigned (20150208)  None (candidate not yet proposed)    View
13555  CVE-2005-2349  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20050722)  None (candidate not yet proposed)    View
79091  CVE-2015-1814  Candidate  The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users.  Assigned (20150217)  None (candidate not yet proposed)    View
13811  CVE-2005-2605  Candidate  Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags.  Assigned (20050817)  None (candidate not yet proposed)    View

Page 19921 of 20943, showing 5 records out of 104715 total, starting on record 99601, ending on 99605

Actions