CVE List

Id CVE No. Status Description Phase Votes Comments Actions
75778  CVE-2014-8477  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20141024)  None (candidate not yet proposed)    View
10498  CVE-2004-2072  Candidate  Cross-site scripting (XSS) vulnerability in index.php for Mambo Open Source 4.6, and possibly earlier versions, allows remote attackers to execute script on other clients via the Itemid parameter.  Assigned (20050519)  None (candidate not yet proposed)    View
76034  CVE-2014-8733  Candidate  Cloudera Manager 5.2.0, 5.2.1, and 5.3.0 stores the LDAP bind password in plaintext in unspecified world-readable files under /etc/hadoop, which allows local users to obtain this password.  Assigned (20141110)  None (candidate not yet proposed)    View
10754  CVE-2004-2328  Candidate  Clearswift MAILsweeper for SMTP before 4.3_13 allows remote attackers to cause a denial of service (infinite loop) via an e-mail with a crafted RAR archive attached.  Assigned (20050816)  None (candidate not yet proposed)    View
76290  CVE-2014-8989  Candidate  The Linux kernel through 3.17.4 does not properly restrict dropping of supplemental group memberships in certain namespace scenarios, which allows local users to bypass intended file permissions by leveraging a POSIX ACL containing an entry for the group category that is more restrictive than the entry for the other category, aka a "negative groups" issue, related to kernel/groups.c, kernel/uid16.c, and kernel/user_namespace.c.  Assigned (20141119)  None (candidate not yet proposed)    View

Page 785 of 20943, showing 5 records out of 104715 total, starting on record 3921, ending on 3925

Actions