CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
49668 | CVE-2011-1756 | Candidate | modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. | Assigned (20110419) | None (candidate not yet proposed) | View | |
49924 | CVE-2011-2012 | Candidate | Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash." | Assigned (20110509) | None (candidate not yet proposed) | View | |
50180 | CVE-2011-2268 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20110602) | None (candidate not yet proposed) | View | |
50436 | CVE-2011-2524 | Candidate | Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI. | Assigned (20110615) | None (candidate not yet proposed) | View | |
50692 | CVE-2011-2780 | Candidate | Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, a different vulnerability than CVE-2011-2744. | Assigned (20110719) | None (candidate not yet proposed) | View |
Page 1535 of 20943, showing 5 records out of 104715 total, starting on record 7671, ending on 7675