CVE List

Id CVE No. Status Description Phase Votes Comments Actions
49420  CVE-2011-1508  Candidate  Microsoft Publisher 2003 SP3, and 2007 SP2 and SP3, does not properly manage memory allocations for function pointers, which allows user-assisted remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Function Pointer Overwrite Vulnerability."  Assigned (20110323)  None (candidate not yet proposed)    View
49676  CVE-2011-1764  Candidate  Format string vulnerability in the dkim_exim_verify_finish function in src/dkim.c in Exim before 4.76 might allow remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via format string specifiers in data used in DKIM logging, as demonstrated by an identity field containing a % (percent) character.  Assigned (20110419)  None (candidate not yet proposed)    View
49932  CVE-2011-2020  Candidate  Cross-site scripting (XSS) vulnerability in TIBCO iProcess Engine before 11.1.3 and iProcess Workspace before 11.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20110509)  None (candidate not yet proposed)    View
50188  CVE-2011-2276  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20110602)  None (candidate not yet proposed)    View
50444  CVE-2011-2532  Candidate  The json.decode function in util/json.lua in Prosody 0.8.x before 0.8.1 might allow remote attackers to cause a denial of service (infinite loop) via invalid JSON data, as demonstrated by truncated data.  Assigned (20110622)  None (candidate not yet proposed)    View

Page 1024 of 20943, showing 5 records out of 104715 total, starting on record 5116, ending on 5120

Actions