NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 40218 | CVE-2013-4661 | CiviCRM 2.0.0 through 4.2.9 and 4.3.0 through 4.3.3 does not properly enforce role-based access control (RBAC) restrictions for default custom searches, which allows remote authenticated users with the "access CiviCRM" permission to bypass intended access restrictions, as demonstrated by accessing custom contribution data without having the "access CiviContribute" permission. | 2 | 4.9 | Medium | 2017-01-18 | 2014-02-21 | View | |
| 11499 | CVE-2011-5239 | CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | 2 | 5.8 | Medium | 2017-01-07 | 2012-11-06 | View | |
| 72287 | CVE-2004-1909 | Claim Anti-Virus (ClamAV) 0.68 and earlier allows remote attackers to cause a denial of service (crash) via certain RAR archives, such as those generated by the Beagle/Bagle worm. | 2 | 2.6 | Low | 2017-07-18 | 2017-07-10 | View | |
| 64449 | CVE-2006-5874 | Clam AntiVirus (ClamAV) 0.88 and earlier allows remote attackers to cause a denial of service (crash) via a malformed base64-encoded MIME attachment that triggers a null pointer dereference. | 2 | 5 | Medium | 2016-12-20 | 2010-09-15 | View | |
| 64952 | CVE-2006-6406 | Clam AntiVirus (ClamAV) 0.88.6 allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file. | 2 | 5 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 2578 of 17672, showing 5 records out of 88360 total, starting on record 12886, ending on 12890