CVE List

Id CVE No. Status Description Phase Votes Comments Actions
78592  CVE-2015-1315  Candidate  Buffer overflow in the charset_to_intern function in unix/unix.c in Info-Zip UnZip 6.10b allows remote attackers to execute arbitrary code via a crafted string, as demonstrated by converting a string from CP866 to UTF-8.  Assigned (20150122)  None (candidate not yet proposed)    View
13312  CVE-2005-2106  Candidate  Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.  Assigned (20050701)  None (candidate not yet proposed)    View
78848  CVE-2015-1571  Candidate  ** DISPUTED ** The CAPWAP DTLS protocol implementation in Fortinet FortiOS 5.0 Patch 7 build 4457 uses the same certificate and private key across different customers" installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the Fortinet_Factory certificate and private key. NOTE: FG-IR-15-002 says "The Fortinet_Factory certificate is unique to each device ... An attacker cannot therefore stage a MitM attack."  Assigned (20150210)  None (candidate not yet proposed)    View
13568  CVE-2005-2362  Candidate  Unknown vulnerability several dissectors in Ethereal 0.9.0 through 0.10.11 allows remote attackers to cause a denial of service (application crash) by reassembling certain packets.  Assigned (20050726)  None (candidate not yet proposed)    View
79104  CVE-2015-1827  Candidate  The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list request for a user that belongs to a large number of groups.  Assigned (20150217)  None (candidate not yet proposed)    View

Page 53 of 20943, showing 5 records out of 104715 total, starting on record 261, ending on 265

Actions