CVE List

Id CVE No. Status Description Phase Votes Comments Actions
49668  CVE-2011-1756  Candidate  modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.  Assigned (20110419)  None (candidate not yet proposed)    View
49924  CVE-2011-2012  Candidate  Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash."  Assigned (20110509)  None (candidate not yet proposed)    View
50180  CVE-2011-2268  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20110602)  None (candidate not yet proposed)    View
50436  CVE-2011-2524  Candidate  Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI.  Assigned (20110615)  None (candidate not yet proposed)    View
50692  CVE-2011-2780  Candidate  Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, a different vulnerability than CVE-2011-2744.  Assigned (20110719)  None (candidate not yet proposed)    View

Page 1535 of 20943, showing 5 records out of 104715 total, starting on record 7671, ending on 7675

Actions