CVE List

Id CVE No. Status Description Phase Votes Comments Actions
58881  CVE-2012-5638  Candidate  The setup_logging function in log.h in SANLock uses world-writable permissions for /var/log/sanlock.log, which allows local users to overwrite the file content or bypass intended disk-quota restrictions via standard filesystem write operations.  Assigned (20121024)  None (candidate not yet proposed)    View
59137  CVE-2012-5894  Candidate  SQL injection vulnerability in hava_post.php in Havalite CMS 1.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the postId parameter.  Assigned (20121117)  None (candidate not yet proposed)    View
59393  CVE-2012-6150  Candidate  The winbind_name_list_to_sid_string_list function in nsswitch/pam_winbind.c in Samba through 4.1.2 handles invalid require_membership_of group names by accepting authentication by any user, which allows remote authenticated users to bypass intended access restrictions in opportunistic circumstances by leveraging an administrator"s pam_winbind configuration-file mistake.  Assigned (20121206)  None (candidate not yet proposed)    View
59649  CVE-2012-6406  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20121216)  None (candidate not yet proposed)    View
59905  CVE-2012-6662  Candidate  Cross-site scripting (XSS) vulnerability in the default content option in jquery.ui.tooltip.js in the Tooltip widget in jQuery UI before 1.10.0 allows remote attackers to inject arbitrary web script or HTML via the title attribute, which is not properly handled in the autocomplete combo box demo.  Assigned (20141114)  None (candidate not yet proposed)    View

Page 155 of 20943, showing 5 records out of 104715 total, starting on record 771, ending on 775

Actions