CVE List

Id CVE No. Status Description Phase Votes Comments Actions
34041  CVE-2008-3924  Candidate  The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web root with insufficient access control, which allows remote attackers to discover (1) account names and (2) password hashes via a direct request for (a) backup/cmme_data.zip or (b) backup/cmme_cmme.zip. NOTE: it was later reported that vector a also affects CMME 1.19.  Assigned (20080904)  None (candidate not yet proposed)    View
99577  CVE-2017-2757  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161201)  None (candidate not yet proposed)    View
34297  CVE-2008-4180  Candidate  Unspecified vulnerability in db.php in NooMS 1.1 allows remote attackers to conduct brute force attacks against passwords via a username in the g_dbuser parameter and a password in the g_dbpwd parameter, and possibly a "localhost" g_dbhost parameter value, related to a "Mysql Remote Brute Force Vulnerability."  Assigned (20080923)  None (candidate not yet proposed)    View
99833  CVE-2017-3013  Candidate  Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an insecure library loading (DLL hijacking) vulnerability in a DLL related to remote logging.  Assigned (20161202)  None (candidate not yet proposed)    View
34553  CVE-2008-4436  Candidate  SQL injection vulnerability in bblog_plugins/builtin.help.php in bBlog 0.7.6 allows remote attackers to execute arbitrary SQL commands via the mod parameter.  Assigned (20081003)  None (candidate not yet proposed)    View

Page 20437 of 20943, showing 5 records out of 104715 total, starting on record 102181, ending on 102185

Actions