CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
13026 | CVE-2005-1820 | Candidate | zboard.php in Zeroboard version 4.1pl2 to 4.1pl5 allows remote attackers to execute arbitrary PHP code via improper quoting when using the preg_replace function. | Assigned (20050601) | None (candidate not yet proposed) | View | |
16609 | CVE-2006-0505 | Candidate | zbattle.net Zbattle client 1.09 SR-1 beta allows remote attackers to cause an unspecified denial of service by rapidly creating and closing a game. | Assigned (20060201) | None (candidate not yet proposed) | View | |
83843 | CVE-2015-6566 | Candidate | zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*. | Assigned (20150821) | None (candidate not yet proposed) | View | |
72745 | CVE-2014-5447 | Candidate | Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103. | Assigned (20140825) | None (candidate not yet proposed) | View | |
72747 | CVE-2014-5449 | Candidate | Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary session data. | Assigned (20140825) | None (candidate not yet proposed) | View |
Page 35 of 20943, showing 5 records out of 104715 total, starting on record 171, ending on 175