CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52238  CVE-2011-4326  Candidate  The udp6_ufo_fragment function in net/ipv6/udp.c in the Linux kernel before 2.6.39, when a certain UDP Fragmentation Offload (UFO) configuration is enabled, allows remote attackers to cause a denial of service (system crash) by sending fragmented IPv6 UDP packets to a bridge device.  Assigned (20111104)  None (candidate not yet proposed)    View
52494  CVE-2011-4582  Candidate  Open redirect vulnerability in the Calendar set page in Moodle 2.1.x before 2.1.3 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via a redirection URL.  Assigned (20111129)  None (candidate not yet proposed)    View
52750  CVE-2011-4838  Candidate  JRuby before 1.6.5.1 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.  Assigned (20111215)  None (candidate not yet proposed)    View
53006  CVE-2011-5094  Candidate  ** DISPUTED ** Mozilla Network Security Services (NSS) 3.x, with certain settings of the SSL_ENABLE_RENEGOTIATION option, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-1473. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment.  Assigned (20120616)  None (candidate not yet proposed)    View
53262  CVE-2012-0019  Candidate  Microsoft Visio Viewer 2010 Gold and SP1 does not properly handle memory during the parsing of files, which allows remote attackers to execute arbitrary code via crafted attributes in a Visio file, aka "VSD File Format Memory Corruption Vulnerability," a different vulnerability than CVE-2012-0020, CVE-2012-0136, CVE-2012-0137, and CVE-2012-0138.  Assigned (20111109)  None (candidate not yet proposed)    View

Page 1185 of 20943, showing 5 records out of 104715 total, starting on record 5921, ending on 5925

Actions