CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76531  CVE-2014-9230  Candidate  Cross-site scripting (XSS) vulnerability in the administration console in the Enforce Server in Symantec Data Loss Prevention (DLP) before 12.5.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20141203)  None (candidate not yet proposed)    View
11251  CVE-2005-0045  Candidate  The Server Message Block (SMB) implementation for Windows NT 4.0, 2000, XP, and Server 2003 does not properly validate certain SMB packets, which allows remote attackers to execute arbitrary code via Transaction responses containing (1) Trans or (2) Trans2 commands, aka the "Server Message Block Vulnerability," and as demonstrated using Trans2 FIND_FIRST2 responses with large file name length fields.  Assigned (20050111)  None (candidate not yet proposed)    View
76787  CVE-2014-9486  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-9447. Reason: This candidate is a duplicate of CVE-2014-9447. Notes: All CVE users should reference CVE-2014-9447 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.  Assigned (20150103)  None (candidate not yet proposed)    View
11507  CVE-2005-0301  Candidate  comersus_backoffice_install10.asp in BackOffice Lite 6.0 and 6.01 allows remote attackers to bypass authentication and gain privileges via a direct request to the program.  Assigned (20050210)  None (candidate not yet proposed)    View
77043  CVE-2014-9742  Candidate  The Miller-Rabin primality check in Botan before 1.10.8 and 1.11.x before 1.11.9 improperly uses a single random base, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via a DH group.  Assigned (20150804)  None (candidate not yet proposed)    View

Page 19314 of 20943, showing 5 records out of 104715 total, starting on record 96566, ending on 96570

Actions