CVE List

Id CVE No. Status Description Phase Votes Comments Actions
55041  CVE-2012-1798  Candidate  The TIFFGetEXIFProperties function in coders/tiff.c in ImageMagick before 6.7.6-3 allows remote attackers to cause a denial of service (out-of-bounds read and crash) via a crafted EXIF IFD in a TIFF image.  Assigned (20120321)  None (candidate not yet proposed)    View
55297  CVE-2012-2054  Candidate  Redmine before 1.3.2 does not properly restrict the use of a hash to provide values for a model"s attributes, which allows remote attackers to set attributes in the (1) Comment, (2) Document, (3) IssueCategory, (4) MembersController, (5) Message, (6) News, (7) TimeEntry, (8) Version, (9) Wiki, (10) UserPreference, or (11) Board model via a modified URL, related to a "mass assignment" vulnerability, a different vulnerability than CVE-2012-0327.  Assigned (20120404)  None (candidate not yet proposed)    View
55553  CVE-2012-2310  Candidate  Cross-site scripting (XSS) vulnerability in the cctags module for Drupal 6.x-1.x before 6.x-1.10 and 7.x-1.x before 7.x-1.10 allows remote authenticated users with certain roles to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20120419)  None (candidate not yet proposed)    View
55809  CVE-2012-2566  Candidate  Bloxx Web Filtering before 5.0.14 does not properly interpret X-Forwarded-For headers during access-control and logging operations for HTTPS connection attempts, which allows remote attackers to bypass intended IP address and domain restrictions, and trigger misleading log entries, via a crafted header.  Assigned (20120509)  None (candidate not yet proposed)    View
56065  CVE-2012-2822  Candidate  The PDF functionality in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.  Assigned (20120519)  None (candidate not yet proposed)    View

Page 152 of 20943, showing 5 records out of 104715 total, starting on record 756, ending on 760

Actions