CVE List

Id CVE No. Status Description Phase Votes Comments Actions
48909  CVE-2011-0997  Candidate  dhclient in ISC DHCP 3.0.x through 4.2.x before 4.2.1-P1, 3.1-ESV before 3.1-ESV-R1, and 4.1-ESV before 4.1-ESV-R2 allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message, as demonstrated by a hostname that is provided to dhclient-script.  Assigned (20110214)  None (candidate not yet proposed)    View
49165  CVE-2011-1253  Candidate  Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5.1, and 4, and Silverlight 4 before 4.0.60831, does not properly restrict inheritance, which allows remote attackers to execute arbitrary code via (1) a crafted XAML browser application (aka XBAP), (2) a crafted ASP.NET application, (3) a crafted .NET Framework application, or (4) a crafted Silverlight application, aka ".NET Framework Class Inheritance Vulnerability."  Assigned (20110304)  None (candidate not yet proposed)    View
49421  CVE-2011-1509  Candidate  The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in cookies, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.  Assigned (20110323)  None (candidate not yet proposed)    View
49677  CVE-2011-1765  Candidate  Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.5, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .shtml at the end of the query string, in conjunction with a modified URI path that has a %2E sequence in place of the . (dot) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1578 and CVE-2011-1587.  Assigned (20110419)  None (candidate not yet proposed)    View
49933  CVE-2011-2021  Candidate  Session fixation vulnerability in TIBCO iProcess Engine before 11.1.3 and iProcess Workspace before 11.3.1 allows remote attackers to hijack web sessions via unspecified vectors.  Assigned (20110509)  None (candidate not yet proposed)    View

Page 1103 of 20943, showing 5 records out of 104715 total, starting on record 5511, ending on 5515

Actions