CVE List

Id CVE No. Status Description Phase Votes Comments Actions
17424  CVE-2006-1320  Candidate  util.c in rssh 2.3.0 in Debian GNU/Linux does not use braces to make a block, which causes a check for CVS to always succeed and allows rsync and rdist to bypass intended access restrictions in rssh.conf.  Assigned (20060319)  None (candidate not yet proposed)    View
81776  CVE-2015-4499  Candidate  Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows remote attackers to obtain the default privileges for an arbitrary domain name by placing that name in a substring of an address, as demonstrated by truncation of an @mozilla.com.example.com address to an @mozilla.com address.  Assigned (20150610)  None (candidate not yet proposed)    View
29566  CVE-2007-6209  Candidate  Util/difflog.pl in zsh 4.3.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files.  Assigned (20071203)  None (candidate not yet proposed)    View
76595  CVE-2014-9294  Candidate  util/ntp-keygen.c in ntp-keygen in NTP before 4.2.7p230 uses a weak RNG seed, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.  Assigned (20141205)  None (candidate not yet proposed)    View
18841  CVE-2006-2737  Candidate  utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary groups, including the administrative group, via a modified groupid parameter when creating a user via the addDB action.  Assigned (20060601)  None (candidate not yet proposed)    View

Page 20364 of 20943, showing 5 records out of 104715 total, starting on record 101816, ending on 101820

Actions