CVE List

Id CVE No. Status Description Phase Votes Comments Actions
53270  CVE-2012-0027  Candidate  The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.  Assigned (20111207)  None (candidate not yet proposed)    View
53526  CVE-2012-0283  Candidate  Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php.  Assigned (20111230)  None (candidate not yet proposed)    View
53782  CVE-2012-0539  Candidate  Unspecified vulnerability in Oracle Sun Solaris 8, 9, and 10 allows local users to affect confidentiality, integrity, and availability via unknown vectors related to (1) bsmconv and (2) bsmunconv.  Assigned (20120111)  None (candidate not yet proposed)    View
54038  CVE-2012-0795  Candidate  Moodle 1.9.x before 1.9.16, 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 does not validate e-mail address settings, which allows remote authenticated users to have an unspecified impact via a crafted address.  Assigned (20120119)  None (candidate not yet proposed)    View
54294  CVE-2012-1051  Candidate  Heap-based buffer overflow in Xjp2.dll in the JPEG2000 plug-in in XnView 1.98.5 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.  Assigned (20120213)  None (candidate not yet proposed)    View

Page 1799 of 20943, showing 5 records out of 104715 total, starting on record 8991, ending on 8995

Actions