CVE List

Id CVE No. Status Description Phase Votes Comments Actions
67087  CVE-2013-7140  Candidate  XML External Entity (XXE) vulnerability in the CalDAV interface in Open-Xchange (OX) AppSuite 7.4.1 and earlier allows remote authenticated users to read portions of arbitrary files via vectors related to the SAX builder and the WebDAV interface. NOTE: this issue has been labeled as both absolute path traversal and XXE, but the root cause may be XXE, since XXE can be exploited to conduct absolute path traversal and other attacks.  Assigned (20131218)  None (candidate not yet proposed)    View
1807  CVE-2000-0229  Entry  gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a utility from gpm-root.        View
67343  CVE-2013-7396  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20140813)  None (candidate not yet proposed)    View
2063  CVE-2000-0485  Entry  Microsoft SQL Server allows local users to obtain database passwords via the Data Transformation Service (DTS) package Properties dialog, aka the "DTS Password" vulnerability.        View
67599  CVE-2014-0190  Candidate  The GIF decoder in QtGui in Qt before 5.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via invalid width and height values in a GIF image.  Assigned (20131203)  None (candidate not yet proposed)    View

Page 1211 of 20943, showing 5 records out of 104715 total, starting on record 6051, ending on 6055

Actions