CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
80255 | CVE-2015-2978 | Candidate | Webservice-DIC yoyaku_v41 allows remote attackers to bypass authentication and complete a conference-room reservation via unspecified vectors, as demonstrated by an "unintentional reservation." | Assigned (20150407) | None (candidate not yet proposed) | View | |
29181 | CVE-2007-5824 | Candidate | webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a stats method action to /xml-rpc with (1) an empty Authorization header line, which triggers a crash in the ws_decodepassword function; or (2) a header line without a ":" character, which triggers a crash in the ws_getheaders function. | Assigned (20071105) | None (candidate not yet proposed) | View | |
11491 | CVE-2005-0285 | Candidate | Webseries Payment Application does not properly restrict privileged operations, which allows remote authenticated users to gain privileges by directly accessing certain URLs. | Assigned (20050210) | None (candidate not yet proposed) | View | |
18139 | CVE-2006-2035 | Candidate | Websense, when configured to permit access to the dynamic content category, allows local users to bypass intended blocking of the Uncategorized category by appending a "/?" sequence to a URL. | Assigned (20060425) | None (candidate not yet proposed) | View | |
47732 | CVE-2010-5148 | Candidate | Websense Web Security and Web Filter before 7.1 Hotfix 21 do not set the secure flag for the Encrypted Session (SSL) cookie in an https session, which makes it easier for remote attackers to capture this cookie by intercepting its transmission within an http session. | Assigned (20120823) | None (candidate not yet proposed) | View |
Page 236 of 20943, showing 5 records out of 104715 total, starting on record 1176, ending on 1180