CVE List

Id CVE No. Status Description Phase Votes Comments Actions
57108  CVE-2012-3865  Candidate  Directory traversal vulnerability in lib/puppet/reports/store.rb in Puppet before 2.6.17 and 2.7.x before 2.7.18, and Puppet Enterprise before 2.5.2, when Delete is enabled in auth.conf, allows remote authenticated users to delete arbitrary files on the puppet master server via a .. (dot dot) in a node name.  Assigned (20120706)  None (candidate not yet proposed)    View
57364  CVE-2012-4121  Candidate  Cisco NX-OS allows local users to gain privileges, and read or modify arbitrary files, via the sed (1) r and (2) w commands, aka Bug IDs CSCts56559, CSCts56565, CSCts56570, and CSCts56574.  Assigned (20120731)  None (candidate not yet proposed)    View
57620  CVE-2012-4377  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20120821)  None (candidate not yet proposed)    View
57876  CVE-2012-4633  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20120824)  None (candidate not yet proposed)    View
58132  CVE-2012-4889  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine Firewall Analyzer 7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) subTab or (2) tab parameter to createAnomaly.do; (3) url, (4) subTab, or (5) tab parameter to mindex.do; (6) tab parameter to index2.do; or (7) port parameter to syslogViewer.do.  Assigned (20120910)  None (candidate not yet proposed)    View

Page 1664 of 20943, showing 5 records out of 104715 total, starting on record 8316, ending on 8320

Actions