CVE List

Id CVE No. Status Description Phase Votes Comments Actions
57089  CVE-2012-3846  Candidate  Cross-site scripting (XSS) vulnerability in index.php in PHP-pastebin 2.1 allows remote attackers to inject arbitrary web script or HTML via the title parameter.  Assigned (20120703)  None (candidate not yet proposed)    View
57345  CVE-2012-4102  Candidate  The activate firmware command in the fabric-interconnect component in Cisco Unified Computing System (UCS) allows local users to gain privileges by embedding commands in an unspecified parameter, aka Bug ID CSCtq02600.  Assigned (20120731)  None (candidate not yet proposed)    View
57601  CVE-2012-4358  Candidate  Sielco Sistemi Winlog Pro SCADA before 2.07.17 and Winlog Lite SCADA before 2.07.17 do not validate the return value of the realloc function, which allows remote attackers to cause a denial of service (invalid 0x00 write operation and daemon crash) or possibly have unspecified other impact via a port-46824 TCP packet with a crafted positive integer after the opcode.  Assigned (20120819)  None (candidate not yet proposed)    View
57857  CVE-2012-4614  Candidate  The default configuration of EMC Smarts Network Configuration Manager (NCM) before 9.1 does not require authentication for database access, which allows remote attackers to have an unspecified impact via a network session.  Assigned (20120824)  None (candidate not yet proposed)    View
58113  CVE-2012-4870  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in FreePBX 2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) context parameter to panel/index_amp.php or (2) panel/dhtml/index.php; (3) clid or (4) clidname parameters to panel/flash/mypage.php; (5) PATH_INFO to admin/views/freepbx_reload.php; or (6) login parameter to recordings/index.php.  Assigned (20120906)  None (candidate not yet proposed)    View

Page 156 of 20943, showing 5 records out of 104715 total, starting on record 776, ending on 780

Actions