CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
2774 | CVE-2000-1207 | Candidate | userhelper in the usermode package on Red Hat Linux executes non-setuid programs as root, which does not activate the security measures in glibc and allows the programs to be exploited via format string vulnerabilities in glibc via the LANG or LC_ALL environment variables (CVE-2000-0844). | Proposed (20020830) | ACCEPT(6) Armstrong, Baker, Cole, Cox, Green, Wall | MODIFY(1) Frech | NOOP(1) Foat | Frech> XF:usermode-userhelper-bypass-security(11089) | View |
4608 | CVE-2002-0216 | Candidate | userinfo.php in XOOPS 1.0 RC1 allows remote attackers to obtain sensitive information via a SQL injection attack in the "uid" parameter. | Proposed (20020502) | ACCEPT(1) Green | NOOP(3) Cole, Foat, Wall | View | |
63546 | CVE-2013-3599 | Candidate | userlogin.jsp in Coursemill Learning Management System (LMS) 6.6 and 6.8 allows remote attackers to gain privileges via a modified user-role value to home.html. | Assigned (20130521) | None (candidate not yet proposed) | View | |
79561 | CVE-2015-2284 | Candidate | userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privileges and execute arbitrary code via unspecified vectors, related to client session handling. | Assigned (20150311) | None (candidate not yet proposed) | View | |
5096 | CVE-2002-0706 | Candidate | UserManager.js in the Web Reports Server for SurfControl SuperScout WebFilter uses weak encryption for administrator functions, which allows remote attackers to decrypt the administrative password using a hard-coded key in a Javascript function. | Modified (20050610) | ACCEPT(1) Baker | NOOP(4) Cole, Cox, Green, Wall | View |
Page 20358 of 20943, showing 5 records out of 104715 total, starting on record 101786, ending on 101790