CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13818 | CVE-2005-2612 | Candidate | Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie. | Assigned (20050817) | None (candidate not yet proposed) | View | |
79354 | CVE-2015-2077 | Candidate | The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qustodio for Windows, Atom Security, Inc. StaffCop 5.8, and other products, uses the same X.509 certificate private key for a root CA certificate across different customers" installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging knowledge of this key, as originally reported for Superfish VisualDiscovery on certain Lenovo Notebook laptop products. | Assigned (20150224) | None (candidate not yet proposed) | View | |
14074 | CVE-2005-2868 | Candidate | ZipTorrent 1.3.7.3 stores sensitive information in plaintext in the pref.txt file, which allows local users to obtain sensitive information such as proxy server information and passwords. | Assigned (20050908) | None (candidate not yet proposed) | View | |
79610 | CVE-2015-2333 | Candidate | Cross-site scripting (XSS) vulnerability in the MyCode editor in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20150318) | None (candidate not yet proposed) | View | |
14330 | CVE-2005-3124 | Candidate | syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file. | Assigned (20051003) | None (candidate not yet proposed) | View |
Page 20485 of 20943, showing 5 records out of 104715 total, starting on record 102421, ending on 102425