CVE List

Id CVE No. Status Description Phase Votes Comments Actions
48404  CVE-2011-0492  Candidate  Tor before 0.2.1.29 and 0.2.2.x before 0.2.2.21-alpha allows remote attackers to cause a denial of service (assertion failure and daemon exit) via blobs that trigger a certain file size, as demonstrated by the cached-descriptors.new file.  Assigned (20110118)  None (candidate not yet proposed)    View
48660  CVE-2011-0748  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in phpList before 2.10.13 allow remote attackers to hijack the authentication of administrators for requests that (1) add or (2) edit administrator accounts.  Assigned (20110202)  None (candidate not yet proposed)    View
48916  CVE-2011-1004  Candidate  The FileUtils.remove_entry_secure method in Ruby 1.8.6 through 1.8.6-420, 1.8.7 through 1.8.7-330, 1.8.8dev, 1.9.1 through 1.9.1-430, 1.9.2 through 1.9.2-136, and 1.9.3dev allows local users to delete arbitrary files via a symlink attack.  Assigned (20110214)  None (candidate not yet proposed)    View
49172  CVE-2011-1260  Candidate  Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "Layout Memory Corruption Vulnerability."  Assigned (20110304)  None (candidate not yet proposed)    View
49428  CVE-2011-1516  Candidate  The kSBXProfileNoNetwork and kSBXProfileNoInternet sandbox profiles in Apple Mac OS X 10.5.x through 10.7.x do not propagate restrictions to all created processes, which allows remote attackers to access network resources via a crafted application, as demonstrated by use of osascript to send Apple events to the launchd daemon, a related issue to CVE-2008-7303.  Assigned (20110323)  None (candidate not yet proposed)    View

Page 1679 of 20943, showing 5 records out of 104715 total, starting on record 8391, ending on 8395

Actions