CVE List

Id CVE No. Status Description Phase Votes Comments Actions
13312  CVE-2005-2106  Candidate  Unknown vulnerability in Drupal 4.5.0 through 4.5.3, 4.6.0, and 4.6.1 allows remote attackers to execute arbitrary PHP code via a public comment or posting.  Assigned (20050701)  None (candidate not yet proposed)    View
78848  CVE-2015-1571  Candidate  ** DISPUTED ** The CAPWAP DTLS protocol implementation in Fortinet FortiOS 5.0 Patch 7 build 4457 uses the same certificate and private key across different customers" installations, which makes it easier for man-in-the-middle attackers to spoof SSL servers by leveraging the Fortinet_Factory certificate and private key. NOTE: FG-IR-15-002 says "The Fortinet_Factory certificate is unique to each device ... An attacker cannot therefore stage a MitM attack."  Assigned (20150210)  None (candidate not yet proposed)    View
13568  CVE-2005-2362  Candidate  Unknown vulnerability several dissectors in Ethereal 0.9.0 through 0.10.11 allows remote attackers to cause a denial of service (application crash) by reassembling certain packets.  Assigned (20050726)  None (candidate not yet proposed)    View
79104  CVE-2015-1827  Candidate  The get_user_grouplist function in the extdom plug-in in FreeIPA before 4.1.4 does not properly reallocate memory when processing user accounts, which allows remote attackers to cause a denial of service (crash) via a group list request for a user that belongs to a large number of groups.  Assigned (20150217)  None (candidate not yet proposed)    View
13824  CVE-2005-2618  Candidate  Multiple stack-based buffer overflows in Autonomy (formerly Verity) KeyView SDK before 9.2.0, as used in Lotus Notes 6.5.4 and 7.0, allow remote attackers to execute arbitrary code via (1) a UUE file containing an encoded file with a long filename handled by uudrdr.dll, (2) a compressed ZIP file with a long filename handled by kvarcve.dll, (3) a TAR archive with a long filename that is extracted to a directory with a long path handled by the TAR reader (tarrdr.dll), (4) an email that contains a long HTTP, FTP, or // link handled by the HTML speed reader (htmsr.dll) or (5) an email containing a crafted long link handled by the HTML speed reader (htmsr.dll).  Assigned (20050817)  None (candidate not yet proposed)    View

Page 630 of 20943, showing 5 records out of 104715 total, starting on record 3146, ending on 3150

Actions