CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
53010 | CVE-2011-5098 | Candidate | chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges for creating admin clients, which allows remote authenticated users to bypass intended access restrictions by leveraging read permission for the validation key and executing a knife client create command with the --admin option. | Assigned (20120808) | None (candidate not yet proposed) | View | |
53266 | CVE-2012-0023 | Candidate | Double free vulnerability in the get_chunk_header function in modules/demux/ty.c in VideoLAN VLC media player 0.9.0 through 1.1.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TiVo (TY) file. | Assigned (20111207) | None (candidate not yet proposed) | View | |
53522 | CVE-2012-0279 | Candidate | Quest Toad for Data Analysts 3.0.1 uses weak permissions (Everyone: Full Control) for the %COMMONPROGRAMFILES%Quest Shared directory, which allows local users to gain privileges via a Trojan horse file. | Assigned (20111230) | None (candidate not yet proposed) | View | |
53778 | CVE-2012-0535 | Candidate | Unspecified vulnerability in the Oracle Application Object Library component in Oracle E-Business Suite 12.0.6 and 12.1.3 allows remote attackers to affect confidentiality via unknown vectors related to Change Password Page. | Assigned (20120111) | None (candidate not yet proposed) | View | |
54034 | CVE-2012-0791 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP before 5.0.18 and Horde Groupware Webmail Edition before 4.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) composeCache, (2) rtemode, or (3) filename_* parameters to the compose page; (4) formname parameter to the contacts popup window; or (5) IMAP mailbox names. NOTE: some of these details are obtained from third party information. | Assigned (20120119) | None (candidate not yet proposed) | View |
Page 1502 of 20943, showing 5 records out of 104715 total, starting on record 7506, ending on 7510