CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
54533 | CVE-2012-1290 | Candidate | Cross-site scripting (XSS) vulnerability in b2b/auction/container.jsp in the Internet Sales (crm.b2b) module in SAP NetWeaver 7.0 allows remote attackers to inject arbitrary web script or HTML via the _loadPage parameter. | Assigned (20120223) | None (candidate not yet proposed) | View | |
54789 | CVE-2012-1546 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20120309) | None (candidate not yet proposed) | View | |
55045 | CVE-2012-1802 | Candidate | Buffer overflow in the embedded web server on the Siemens Scalance X Industrial Ethernet switch X414-3E before 3.7.1, X308-2M before 3.7.2, X-300EEC before 3.7.2, XR-300 before 3.7.2, and X-300 before 3.7.2 allows remote attackers to cause a denial of service (device reboot) or possibly execute arbitrary code via a malformed URL. | Assigned (20120321) | None (candidate not yet proposed) | View | |
55301 | CVE-2012-2058 | Candidate | The Ubercart Payflow module for Drupal does not use a secure token, which allows remote attackers to forge payments via unspecified vectors. | Assigned (20120404) | None (candidate not yet proposed) | View | |
55557 | CVE-2012-2314 | Candidate | The bootloader configuration module (pyanaconda/bootloader.py) in Anaconda uses 755 permissions for /etc/grub.d, which allows local users to obtain password hashes and conduct brute force password guessing attacks. | Assigned (20120419) | None (candidate not yet proposed) | View |
Page 1616 of 20943, showing 5 records out of 104715 total, starting on record 8076, ending on 8080