CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47884  CVE-2010-5300  Candidate  Stack-based buffer overflow in Jzip 1.3 through 2.0.0.132900 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long file name in a zip archive.  Assigned (20140611)  None (candidate not yet proposed)    View
48140  CVE-2011-0228  Candidate  The Data Security component in Apple iOS before 4.2.10 and 4.3.x before 4.3.5 does not check the basicConstraints parameter during validation of X.509 certificate chains, which allows man-in-the-middle attackers to spoof an SSL server by using a non-CA certificate to sign a certificate for an arbitrary domain.  Assigned (20101223)  None (candidate not yet proposed)    View
48396  CVE-2011-0484  Candidate  Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly perform DOM node removal, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that lead to a "stale rendering node."  Assigned (20110114)  None (candidate not yet proposed)    View
48652  CVE-2011-0740  Candidate  Cross-site scripting (XSS) vulnerability in magpie/scripts/magpie_slashbox.php in RSS Feed Reader 0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the rss_url parameter.  Assigned (20110201)  None (candidate not yet proposed)    View
48908  CVE-2011-0996  Candidate  dhcpcd before 5.2.12 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message.  Assigned (20110214)  None (candidate not yet proposed)    View

Page 1035 of 20943, showing 5 records out of 104715 total, starting on record 5171, ending on 5175

Actions