CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13214 | CVE-2005-2008 | Candidate | Yaws Webserver 1.55 and earlier allows remote attackers to obtain the source code for yaws scripts via a request to a yaw script with a trailing %00 (null). | Assigned (20050620) | None (candidate not yet proposed) | View | |
21833 | CVE-2006-5729 | Candidate | Yazd Discussion Forum before 3.0 beta does not properly manage forum permissions, which allows remote authenticated users to (1) reply to a message in an arbitrary forum, if authorized to create a message in any forum; and (2) perform certain unauthorized forum actions, related to an "error in how the permissions were assembled" that assigns extra permissions to users. | Assigned (20061106) | None (candidate not yet proposed) | View | |
11068 | CVE-2004-2642 | Candidate | Yeemp 0.9.9 and earlier does not properly encrypt inbound files, which allows remote attackers to spoof the identity of the sender. | Assigned (20051204) | None (candidate not yet proposed) | View | |
35990 | CVE-2008-5873 | Candidate | Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galleta[sesion] cookie that has a value beginning with 1:1: followed by a username. | Assigned (20090108) | None (candidate not yet proposed) | View | |
6228 | CVE-2002-1846 | Candidate | Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php. | Assigned (20050629) | None (candidate not yet proposed) | View |
Page 20902 of 20943, showing 5 records out of 104715 total, starting on record 104506, ending on 104510