CVE List

Id CVE No. Status Description Phase Votes Comments Actions
81914  CVE-2015-4637  Candidate  The REST API in F5 BIG-IQ Cloud, Device, and Security 4.4.0 and 4.5.0 before HF2 and ADC 4.5.0 before HF2, when configured for LDAP remote authentication and the LDAP server allows anonymous BIND operations, allows remote attackers to obtain an authentication token for arbitrary users by guessing an LDAP user account name.  Assigned (20150616)  None (candidate not yet proposed)    View
16634  CVE-2006-0530  Candidate  Computer Associates (CA) Message Queuing (CAM / CAFT) before 1.07 Build 220_16 and 1.11 Build 29_20, as used in multiple CA products, allows remote attackers to cause a denial of service via spoofed CAM control messages.  Assigned (20060202)  None (candidate not yet proposed)    View
82170  CVE-2015-4893  Candidate  Unspecified vulnerability in Oracle Java SE 6u101, 7u85, and 8u60; Java SE Embedded 8u51; and JRockit R28.3.7 allows remote attackers to affect availability via vectors related to JAXP, a different vulnerability than CVE-2015-4803 and CVE-2015-4911.  Assigned (20150624)  None (candidate not yet proposed)    View
16890  CVE-2006-0786  Candidate  Incomplete blacklist vulnerability in include.php in PHPKIT 1.6.1 Release 2 and earlier, with allow_url_fopen enabled, allows remote attackers to conduct PHP remote file include attacks via a path parameter that specifies a (1) UNC share or (2) ftps URL, which bypasses the check for "http://", "ftp://", and "https://" URLs.  Assigned (20060219)  None (candidate not yet proposed)    View
82426  CVE-2015-5149  Candidate  Directory traversal vulnerability in Zoho ManageEngine SupportCenter Plus 7.90 allows remote authenticated users to write to arbitrary files via a .. (dot dot) in the component parameter in the Request component to workorder/Attachment.jsp.  Assigned (20150630)  None (candidate not yet proposed)    View

Page 20466 of 20943, showing 5 records out of 104715 total, starting on record 102326, ending on 102330

Actions