CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39371  CVE-2009-1936  Candidate  _functions.php in cpCommerce 1.2.x, possibly including 1.2.9, sends a redirect but does not exit when it is called directly, which allows remote attackers to bypass a protection mechanism to conduct remote file inclusion and directory traversal attacks, execute arbitrary PHP code, or read arbitrary files via the GLOBALS[prefix] parameter, a different vector than CVE-2003-1500.  Assigned (20090605)  None (candidate not yet proposed)    View
36590  CVE-2008-6473  Candidate  _blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary users via a modified "a" parameter with a "%" wildcard symbol in the b parameter.  Assigned (20090316)  None (candidate not yet proposed)    View
31277  CVE-2008-1160  Candidate  ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a user, which allows remote attackers to gain privileges.  Assigned (20080305)  None (candidate not yet proposed)    View
4830  CVE-2002-0438  Candidate  ZyXEL ZyWALL 10 before 3.50 allows remote attackers to cause a denial of service via an ARP packet with the firewall"s IP address and an incorrect MAC address, which causes the firewall to disable the LAN interface.  Proposed (20020611)  ACCEPT(1) Frech | NOOP(4) Cole, Cox, Foat, Wall | REVIEWING(1) Green    View
87740  CVE-2016-10227  Candidate  Zyxel USG50 Security Appliance and NWA3560-N Access Point allow remote attackers to cause a denial of service (CPU consumption) via a flood of ICMPv4 Port Unreachable packets.  Assigned (20170218)  None (candidate not yet proposed)    View

Page 2 of 20943, showing 5 records out of 104715 total, starting on record 6, ending on 10

<<first 1 | 2 | 3 | 4 | 5 | 6 | 7 | 8 | 9 last>>

Actions