CVE List

Id CVE No. Status Description Phase Votes Comments Actions
71174  CVE-2014-3878  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the web client interface in Ipswitch IMail Server 12.3 and 12.4, possibly before 12.4.1.15, allow remote attackers to inject arbitrary web script or HTML via (1) the Name field in an add new contact action in the Contacts section or unspecified vectors in (2) an Add Group task in the Contacts section, (3) an add new event action in the Calendar section, or (4) the Task section.  Assigned (20140527)  None (candidate not yet proposed)    View
71430  CVE-2014-4134  Candidate  Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."  Assigned (20140612)  None (candidate not yet proposed)    View
6150  CVE-2002-1768  Candidate  Cisco IOS 11.1 through 12.2, when HSRP support is not enabled, allows remote attackers to cause a denial of service (CPU consumption) via randomly sized UDP packets to the Hot Standby Routing Protocol (HSRP) port 1985.  Assigned (20050621)  None (candidate not yet proposed)    View
71686  CVE-2014-4390  Candidate  Bluetooth in Apple OS X before 10.9.5 does not properly validate API calls, which allows attackers to execute arbitrary code in a privileged context via a crafted application.  Assigned (20140620)  None (candidate not yet proposed)    View
6406  CVE-2002-2024  Candidate  Horde IMP 2.2.7 allows remote attackers to obtain the full web root pathname via an HTTP request for (1) poppassd.php3, (2) login.php3?reason=chpass2, (3) spelling.php3, and (4) ldap.search.php3?ldap_serv=nonsense which leaks the information in error messages.  Assigned (20050714)  None (candidate not yet proposed)    View

Page 488 of 20943, showing 5 records out of 104715 total, starting on record 2436, ending on 2440

Actions