CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
67329 | CVE-2013-7382 | Candidate | VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for the (1) VDAD and (2) VDCL users, which makes it easier for remote attackers to obtain access. | Assigned (20140517) | None (candidate not yet proposed) | View | |
64415 | CVE-2013-4468 | Candidate | VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in the extension parameter in an OriginateVDRelogin action to manager_send.php. | Assigned (20130612) | None (candidate not yet proposed) | View | |
36946 | CVE-2008-6829 | Candidate | VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "//" (forward slash, backward slash, forward slash). NOTE: this might be the same issue as CVE-2008-2031. | Assigned (20090608) | None (candidate not yet proposed) | View | |
32148 | CVE-2008-2031 | Candidate | VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NULL pointer dereference. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | Assigned (20080430) | None (candidate not yet proposed) | View | |
36877 | CVE-2008-6760 | Candidate | ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add and save action for a shopping cart in cart_save.php, which reveals the SQL table names in an error message, related to code that mishandles the lack of a user_id parameter. | Assigned (20090428) | None (candidate not yet proposed) | View |
Page 554 of 20943, showing 5 records out of 104715 total, starting on record 2766, ending on 2770