CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52494  CVE-2011-4582  Candidate  Open redirect vulnerability in the Calendar set page in Moodle 2.1.x before 2.1.3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a redirection URL.  Assigned (20111129)  None (candidate not yet proposed)    View
52750  CVE-2011-4838  Candidate  JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.  Assigned (20111215)  None (candidate not yet proposed)    View
53006  CVE-2011-5094  Candidate  ** DISPUTED ** Mozilla Network Security Services (NSS) 3.x, with certain settings of the SSL_ENABLE_RENEGOTIATION option, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-1473. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment.  Assigned (20120616)  None (candidate not yet proposed)    View
53262  CVE-2012-0019  Candidate  Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0020, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.  Assigned (20111109)  None (candidate not yet proposed)    View
53518  CVE-2012-0275  Candidate  Heap-based buffer overflow in Photoshop.exe in Adobe Photoshop CS5 12.x before 12.0.5, CS5.1 12.1.x before 12.1.1, and CS6 13.x before 13.0.1 allows remote attackers to execute arbitrary code via a crafted TIFF image with SGI24LogLum compression.  Assigned (20111230)  None (candidate not yet proposed)    View

Page 1183 of 20943, showing 5 records out of 104715 total, starting on record 5911, ending on 5915

Actions