CVE List

Id CVE No. Status Description Phase Votes Comments Actions
1538  CVE-1999-1558  Candidate  Vulnerability in loginout in Digital OpenVMS 7.1 and earlier allows unauthorized access when external authentication is enabled.  Modified (20020218-01)  ACCEPT(3) Cole, Foat, Stracener | MODIFY(1) Frech | NOOP(1) Wall  Frech> XF:openvms-loginout-unauth-access(7151)  View
67074  CVE-2013-7127  Candidate  Apple Safari 6.0.5 on Mac OS X 10.7.5 and 10.8.5 stores cleartext credentials in LastSession.plist, which allows local users to obtain sensitive information by reading this file.  Assigned (20131217)  None (candidate not yet proposed)    View
1794  CVE-2000-0216  Candidate  Microsoft email clients in Outlook, Exchange, and Windows Messaging automatically respond to Read Receipt and Delivery Receipt tags, which could allow an attacker to flood a mail system with responses by forging a Read Receipt request that is redirected to a large distribution list.  Proposed (20000322)  ACCEPT(1) Cole | MODIFY(1) Frech | NOOP(2) Baker, Ozancin | REJECT(3) Blake, LeBlanc, Levy | REVIEWING(1) Wall  Blake> This is a configuration issue. Should the fact that NT can be configured | to accept a blank Admin password have a CVE entry? | LeBlanc> This is documented as bad practice - if you have a wide distribution | mailing list, you should only allow certain users to send mail to it. | I don"t think we want to start listing all possible admin errors as | vulnerabilities. | Frech> XF:microsoft-mail-client-dos(4893) | Levy> I agree with all the above comments. Furthermore the delivery status | notification RFC makes it clear that mailing list software should | strip messages from DSN headers. I assume Microsoft"s products are | using the DSN standard and not something else.  View
67330  CVE-2013-7383  Candidate  x2gocleansessions in X2Go Server before 4.0.0.8 and 4.0.1.x before 4.0.1.10 allows remote authenticated users to gain privileges via unspecified vectors, possibly related to backticks.  Assigned (20140519)  None (candidate not yet proposed)    View
67586  CVE-2014-0177  Candidate  The am function in lib/hub/commands.rb in hub before 1.12.1 allows local users to overwrite arbitrary files via a symlink attack on a temporary patch file.  Assigned (20131203)  None (candidate not yet proposed)    View

Page 162 of 20943, showing 5 records out of 104715 total, starting on record 806, ending on 810

Actions