CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13299 | CVE-2005-2093 | Candidate | Oracle 9i Application Server (Oracle9iAS) 9.0.2 allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Application Server to incorrectly handle and forward the body of the request in a way that causes the receiving server to process it as a separate HTTP request, aka "HTTP Request Smuggling." | Assigned (20050630) | None (candidate not yet proposed) | View | |
78835 | CVE-2015-1558 | Candidate | Asterisk Open Source 12.x before 12.8.1 and 13.x before 13.1.1, when using the PJSIP channel driver, does not properly reclaim RTP ports, which allows remote authenticated users to cause a denial of service (file descriptor consumption) via an SDP offer containing only incompatible codecs. | Assigned (20150208) | None (candidate not yet proposed) | View | |
13555 | CVE-2005-2349 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20050722) | None (candidate not yet proposed) | View | |
79091 | CVE-2015-1814 | Candidate | The API token-issuing service in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to gain privileges via a "forced API token change" involving anonymous users. | Assigned (20150217) | None (candidate not yet proposed) | View | |
13811 | CVE-2005-2605 | Candidate | Unknown vulnerability in Lasso Professional Server8.0.4 and 8.0.5 allows attackers to bypass authentication, related to [Auth] tags. | Assigned (20050817) | None (candidate not yet proposed) | View |
Page 19921 of 20943, showing 5 records out of 104715 total, starting on record 99601, ending on 99605