CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67329  CVE-2013-7382  Candidate  VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for the (1) VDAD and (2) VDCL users, which makes it easier for remote attackers to obtain access.  Assigned (20140517)  None (candidate not yet proposed)    View
64415  CVE-2013-4468  Candidate  VICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier allows remote authenticated users to execute arbitrary commands via shell metacharacters in the extension parameter in an OriginateVDRelogin action to manager_send.php.  Assigned (20130612)  None (candidate not yet proposed)    View
36946  CVE-2008-6829  Candidate  VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "//" (forward slash, backward slash, forward slash). NOTE: this might be the same issue as CVE-2008-2031.  Assigned (20090608)  None (candidate not yet proposed)    View
32148  CVE-2008-2031  Candidate  VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NULL pointer dereference. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20080430)  None (candidate not yet proposed)    View
36877  CVE-2008-6760  Candidate  ViArt Shop (aka Shopping Cart) 3.5 allows remote attackers to obtain sensitive information via an unauthenticated add and save action for a shopping cart in cart_save.php, which reveals the SQL table names in an error message, related to code that mishandles the lack of a user_id parameter.  Assigned (20090428)  None (candidate not yet proposed)    View

Page 554 of 20943, showing 5 records out of 104715 total, starting on record 2766, ending on 2770

Actions