CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
49420 | CVE-2011-1508 | Candidate | Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, does not properly manage memory allocations for function pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Function Pointer Overwrite Vulnerability." | Assigned (20110323) | None (candidate not yet proposed) | View | |
49676 | CVE-2011-1764 | Candidate | Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a % (percent) character. | Assigned (20110419) | None (candidate not yet proposed) | View | |
49932 | CVE-2011-2020 | Candidate | Cross-site scripting (XSS) vulnerability in TIBCO iProcess Engine before 11.1.3 and iProcess Workspace before 11.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20110509) | None (candidate not yet proposed) | View | |
50188 | CVE-2011-2276 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20110602) | None (candidate not yet proposed) | View | |
50444 | CVE-2011-2532 | Candidate | The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite loop) via invalid JSON data, as demonstrated by truncated data. | Assigned (20110622) | None (candidate not yet proposed) | View |
Page 1024 of 20943, showing 5 records out of 104715 total, starting on record 5116, ending on 5120