NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
40218  CVE-2013-4661  CiviCRM 2.0.0 through 4.2.9 and 4.3.0 through 4.3.3 does not properly enforce role-based access control (RBAC) restrictions for default custom searches, which allows remote authenticated users with the "access CiviCRM" permission to bypass intended access restrictions, as demonstrated by accessing custom contribution data without having the "access CiviContribute" permission.    4.9  Medium  2017-01-18  2014-02-21  View
11499  CVE-2011-5239  CiviCRM 4.0.5 and 4.1.1 does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.    5.8  Medium  2017-01-07  2012-11-06  View
72287  CVE-2004-1909  Claim Anti-Virus (ClamAV) 0.68 and earlier allows remote attackers to cause a denial of service (crash) via certain RAR archives, such as those generated by the Beagle/Bagle worm.    2.6  Low  2017-07-18  2017-07-10  View
64449  CVE-2006-5874  Clam AntiVirus (ClamAV) 0.88 and earlier allows remote attackers to cause a denial of service (crash) via a malformed base64-encoded MIME attachment that triggers a null pointer dereference.    Medium  2016-12-20  2010-09-15  View
64952  CVE-2006-6406  Clam AntiVirus (ClamAV) 0.88.6 allows remote attackers to bypass virus detection by inserting invalid characters into base64 encoded content in a multipart/mixed MIME file, as demonstrated with the EICAR test file.    Medium  2016-12-20  2011-03-07  View

Page 2578 of 17672, showing 5 records out of 88360 total, starting on record 12886, ending on 12890

Actions