CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13818  CVE-2005-2612  Candidate  Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP code via the cache_lastpostdate[server] cookie.  Assigned (20050817)  None (candidate not yet proposed)    View
79354  CVE-2015-2077  Candidate  The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qustodio for Windows, Atom Security, Inc. StaffCop 5.8, and other products, uses the same X.509 certificate private key for a root CA certificate across different customers" installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging knowledge of this key, as originally reported for Superfish VisualDiscovery on certain Lenovo Notebook laptop products.  Assigned (20150224)  None (candidate not yet proposed)    View
14074  CVE-2005-2868  Candidate  ZipTorrent 1.3.7.3 stores sensitive information in plaintext in the pref.txt file, which allows local users to obtain sensitive information such as proxy server information and passwords.  Assigned (20050908)  None (candidate not yet proposed)    View
79610  CVE-2015-2333  Candidate  Cross-site scripting (XSS) vulnerability in the MyCode editor in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20150318)  None (candidate not yet proposed)    View
14330  CVE-2005-3124  Candidate  syslogtocern in Acme thttpd before 2.23 allows local users to write arbitrary files via a symlink attack on a temporary file.  Assigned (20051003)  None (candidate not yet proposed)    View

Page 20485 of 20943, showing 5 records out of 104715 total, starting on record 102421, ending on 102425

Actions