CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13026  CVE-2005-1820  Candidate  zboard.php in Zeroboard version 4.1pl2 to 4.1pl5 allows remote attackers to execute arbitrary PHP code via improper quoting when using the preg_replace function.  Assigned (20050601)  None (candidate not yet proposed)    View
16609  CVE-2006-0505  Candidate  zbattle.net Zbattle client 1.09 SR-1 beta allows remote attackers to cause an unspecified denial of service by rapidly creating and closing a game.  Assigned (20060201)  None (candidate not yet proposed)    View
83843  CVE-2015-6566  Candidate  zarafa-autorespond in Zarafa Collaboration Platform (ZCP) before 7.2.1 allows local users to gain privileges via a symlink attack on /tmp/zarafa-vacation-*.  Assigned (20150821)  None (candidate not yet proposed)    View
72745  CVE-2014-5447  Candidate  Zarafa WebAccess 7.1.10 and WebApp 1.6 beta uses weak permissions (644) for config.php, which allows local users to obtain sensitive information by reading the PHP session files. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-0103.  Assigned (20140825)  None (candidate not yet proposed)    View
72747  CVE-2014-5449  Candidate  Zarafa WebAccess 4.1 and WebApp uses world-readable permissions for the files in their tmp directory, which allows local users to obtain sensitive information by reading temporary session data.  Assigned (20140825)  None (candidate not yet proposed)    View

Page 35 of 20943, showing 5 records out of 104715 total, starting on record 171, ending on 175

Actions