CVE List

Id CVE No. Status Description Phase Votes Comments Actions
55552  CVE-2012-2309  Candidate  Cross-site scripting (XSS) vulnerability in the Glossify Internal Links Auto SEO module for Drupal 6.x-2.5 and earlier allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20120419)  None (candidate not yet proposed)    View
55808  CVE-2012-2565  Candidate  Bloxx Web Filtering before 5.0.14 does not use a salt during calculation of a password hash, which makes it easier for context-dependent attackers to determine cleartext passwords via a rainbow-table approach.  Assigned (20120509)  None (candidate not yet proposed)    View
56064  CVE-2012-2821  Candidate  The autofill implementation in Google Chrome before 20.0.1132.43 does not properly display text, which has unspecified impact and remote attack vectors.  Assigned (20120519)  None (candidate not yet proposed)    View
56320  CVE-2012-3077  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20120530)  None (candidate not yet proposed)    View
56576  CVE-2012-3333  Candidate  CRLF injection vulnerability in IBM Maximo Asset Management 7.x before 7.5.0.6 and SmartCloud Control Desk 7.x before 7.5.0.3 and 7.5.1.x before 7.5.1.2 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted parameter in a URL.  Assigned (20120607)  None (candidate not yet proposed)    View

Page 1230 of 20943, showing 5 records out of 104715 total, starting on record 6146, ending on 6150

Actions