CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76289  CVE-2014-8988  Candidate  MantisBT before 1.2.18 allows remote authenticated users to bypass the $g_download_attachments_threshold and $g_view_attachments_threshold restrictions and read attachments for private projects by leveraging access to a project that does not restrict access to attachments and a request to the download URL.  Assigned (20141119)  None (candidate not yet proposed)    View
11009  CVE-2004-2583  Candidate  SMTP service in SmarterTools SmarterMail 1.6.1511 and 1.6.1529 allows remote attackers to cause a denial of service (CPU consumption) via a large number of simultaneous open connections to TCP port 25.  Assigned (20051128)  None (candidate not yet proposed)    View
76545  CVE-2014-9244  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141203)  None (candidate not yet proposed)    View
11265  CVE-2005-0059  Candidate  Buffer overflow in the Message Queuing component of Microsoft Windows 2000 and Windows XP SP1 allows remote attackers to execute arbitrary code via a crafted message.  Assigned (20050111)  None (candidate not yet proposed)    View
76801  CVE-2014-9500  Candidate  Cross-site scripting (XSS) vulnerability in the Moip module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to the notification page callback.  Assigned (20150103)  None (candidate not yet proposed)    View

Page 127 of 20943, showing 5 records out of 104715 total, starting on record 631, ending on 635

Actions