CVE List

Id CVE No. Status Description Phase Votes Comments Actions
54533  CVE-2012-1290  Candidate  Cross-site scripting (XSS) vulnerability in b2b/auction/container.jsp in the Internet Sales (crm.b2b) module in SAP NetWeaver 7.0 allows remote attackers to inject arbitrary web script or HTML via the _loadPage parameter.  Assigned (20120223)  None (candidate not yet proposed)    View
54789  CVE-2012-1546  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20120309)  None (candidate not yet proposed)    View
55045  CVE-2012-1802  Candidate  Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a malformed URL.  Assigned (20120321)  None (candidate not yet proposed)    View
55301  CVE-2012-2058  Candidate  The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors.  Assigned (20120404)  None (candidate not yet proposed)    View
55557  CVE-2012-2314  Candidate  The bootloader configuration module (pyanaconda/bootloader.py) in Anaconda uses 755 permissions for /etc/grub.d, which allows local users to obtain password hashes and conduct brute force password guessing attacks.  Assigned (20120419)  None (candidate not yet proposed)    View

Page 1616 of 20943, showing 5 records out of 104715 total, starting on record 8076, ending on 8080

Actions