CVE List

Id CVE No. Status Description Phase Votes Comments Actions
92469  CVE-2016-5650  Candidate  ZModo ZP-NE14-S and ZP-IBH-13W devices do not enforce a WPA2 configuration setting, which allows remote attackers to trigger association with an arbitrary access point by using a recognized SSID value.  Assigned (20160616)  None (candidate not yet proposed)    View
84331  CVE-2015-7054  Candidate  zlib in the Compression component in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 does not initialize memory for an unspecified data structure, which allows remote attackers to execute arbitrary code via a crafted web site.  Assigned (20150916)  None (candidate not yet proposed)    View
13302  CVE-2005-2096  Candidate  zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.  Assigned (20050630)  None (candidate not yet proposed)    View
37241  CVE-2008-7124  Candidate  zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allows remote attackers to gain administrator privileges via a direct request, as demonstrated by adding a new administrator.  Assigned (20090831)  None (candidate not yet proposed)    View
23900  CVE-2007-0543  Candidate  ZixForum 1.14 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for Zixforum.mdb. NOTE: a followup post suggests that this issue only occurs if the administrator does not properly follow installation directions.  Assigned (20070129)  None (candidate not yet proposed)    View

Page 21 of 20943, showing 5 records out of 104715 total, starting on record 101, ending on 105

Actions