CVE List

Id CVE No. Status Description Phase Votes Comments Actions
55055  CVE-2012-1812  Candidate  eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to obtain sensitive cleartext information via a session on TCP port 12000.  Assigned (20120321)  None (candidate not yet proposed)    View
55311  CVE-2012-2068  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in fancy_slide.module in the Fancy Slide module before 6.x-2.7 for Drupal allow remote authenticated users with the administer fancy_slide permission to inject arbitrary web script or HTML via the (1) node_title or (2) nodequeue_title parameter.  Assigned (20120404)  None (candidate not yet proposed)    View
55567  CVE-2012-2324  Candidate  Multiple SQL injection vulnerabilities in MyBB (aka MyBulletinBoard) before 1.6.7 allow remote administrators to execute arbitrary SQL commands via unspecified vectors in the (1) user search or (2) Mail Log in the Admin Control Panel (ACP).  Assigned (20120419)  None (candidate not yet proposed)    View
55823  CVE-2012-2580  Candidate  Cross-site scripting (XSS) vulnerability in the Postie plugin 1.4.3, and possibly before 1.5.15, for WordPress allows remote attackers to inject arbitrary web script or HTML via the From field of an email.  Assigned (20120509)  None (candidate not yet proposed)    View
56079  CVE-2012-2836  Candidate  The exif_data_load_data function in exif-data.c in the EXIF Tag Parsing Library (aka libexif) before 0.6.21 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly obtain sensitive information from process memory via crafted EXIF tags in an image.  Assigned (20120519)  None (candidate not yet proposed)    View

Page 1262 of 20943, showing 5 records out of 104715 total, starting on record 6306, ending on 6310

Actions