CVE List

Id CVE No. Status Description Phase Votes Comments Actions
18841  CVE-2006-2737  Candidate  utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary groups, including the administrative group, via a modified groupid parameter when creating a user via the addDB action.  Assigned (20060601)  None (candidate not yet proposed)    View
76595  CVE-2014-9294  Candidate  util/ntp-keygen.c in ntp-keygen in NTP before 4.2.7p230 uses a weak RNG seed, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a brute-force attack.  Assigned (20141205)  None (candidate not yet proposed)    View
29566  CVE-2007-6209  Candidate  Util/difflog.pl in zsh 4.3.4 allows local users to overwrite arbitrary files via a symlink attack on temporary files.  Assigned (20071203)  None (candidate not yet proposed)    View
81776  CVE-2015-4499  Candidate  Util.pm in Bugzilla 2.x, 3.x, and 4.x before 4.2.15, 4.3.x and 4.4.x before 4.4.10, and 5.x before 5.0.1 mishandles long e-mail addresses during account registration, which allows remote attackers to obtain the default privileges for an arbitrary domain name by placing that name in a substring of an address, as demonstrated by truncation of an @mozilla.com.example.com address to an @mozilla.com address.  Assigned (20150610)  None (candidate not yet proposed)    View
17424  CVE-2006-1320  Candidate  util.c in rssh 2.3.0 in Debian GNU/Linux does not use braces to make a block, which causes a check for CVS to always succeed and allows rsync and rdist to bypass intended access restrictions in rssh.conf.  Assigned (20060319)  None (candidate not yet proposed)    View

Page 580 of 20943, showing 5 records out of 104715 total, starting on record 2896, ending on 2900

Actions