CVE List

Id CVE No. Status Description Phase Votes Comments Actions
11017  CVE-2004-2591  Candidate  The data-overwrite capability of ButtUglySoftware CleanCache 2.19 does not properly overwrite data in files, which allows attackers to recover the data.  Assigned (20051129)  None (candidate not yet proposed)    View
76553  CVE-2014-9252  Candidate  Zenoss Core through 5 Beta 3 stores cleartext passwords in the session database, which might allow local users to obtain sensitive information by reading database entries, aka ZEN-15416.  Assigned (20141203)  None (candidate not yet proposed)    View
11273  CVE-2005-0067  Candidate  The original design of TCP does not require that port numbers be assigned randomly (aka "Port randomization"), which makes it easier for attackers to forge ICMP error messages for specific TCP connections and cause a denial of service, as demonstrated using (1) blind connection-reset attacks with forged "Destination Unreachable" messages, (2) blind throughput-reduction attacks with forged "Source Quench" messages, or (3) blind throughput-reduction attacks with forged ICMP messages that cause the Path MTU to be reduced. NOTE: CVE-2004-0790, CVE-2004-0791, and CVE-2004-1060 have been SPLIT based on different attacks; CVE-2005-0065, CVE-2005-0066, CVE-2005-0067, and CVE-2005-0068 are related identifiers that are SPLIT based on the underlying vulnerability. While CVE normally SPLITs based on vulnerability, the attack-based identifiers exist due to the variety and number of affected implementations and solutions that address the attacks instead of the underlying vulnerabilities.  Assigned (20050113)  None (candidate not yet proposed)    View
76809  CVE-2014-9508  Candidate  The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set and using a homepage with links that only contain anchors, allows remote attackers to change URLs to arbitrary domains for those links via unknown vectors.  Assigned (20150104)  None (candidate not yet proposed)    View
11529  CVE-2005-0323  Candidate  Cross-site scripting (XSS) vulnerability in Infinite Mobile Delivery Webmail 2.6 allows remote attackers to inject arbitrary web script or HTML via the URL.  Assigned (20050210)  None (candidate not yet proposed)    View

Page 742 of 20943, showing 5 records out of 104715 total, starting on record 3706, ending on 3710

Actions