NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
25860  CVE-2015-4418  Zoho NetFlow Analyzer build 10250 and earlier does not have an off autocomplete attribute for a password field, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.    Medium  2017-01-19  2016-12-30  View
82038  CVE-2016-6603  ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.    Medium  2017-02-08  2017-02-07  View
82037  CVE-2016-6602  ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependent attackers to obtain cleartext passwords by leveraging access to WEB-INF/conf/securitydbData.xml. NOTE: this issue can be combined with CVE-2016-6601 for a remote exploit.    Medium  2017-02-08  2017-02-07  View
56483  CVE-2007-4358  Zoidcom 0.6.7 and earlier allows remote attackers to cause a denial of service (application crash) via a JOIN packet (aka connection packet) containing 0x69 in the ninth byte, which triggers a "double-delete" of trace data, a different vulnerability than CVE-2005-1643.    4.3  Medium  2017-01-07  2008-09-05  View
50890  CVE-2009-3704  ZoIPer 2.22, and possibly other versions before 2.24 Library 5324, allows remote attackers to cause a denial of service (crash) via a SIP INVITE request with an empty Call-Info header.    Medium  2017-01-07  2009-10-19  View

Page 17655 of 17672, showing 5 records out of 88360 total, starting on record 88271, ending on 88275

Actions