CVE List

Id CVE No. Status Description Phase Votes Comments Actions
58595  CVE-2012-5352  Candidate  Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack."  Assigned (20121009)  None (candidate not yet proposed)    View
58851  CVE-2012-5608  Candidate  Cross-site scripting (XSS) vulnerability in apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via arbitrary POST parameters.  Assigned (20121024)  None (candidate not yet proposed)    View
59107  CVE-2012-5864  Candidate  The management web pages on the Sinapsi eSolar Light Photovoltaic System Monitor (aka Schneider Electric Ezylog photovoltaic SCADA management server), Sinapsi eSolar, and Sinapsi eSolar DUO with firmware before 2.0.2870_2.2.12 do not require authentication, which allows remote attackers to obtain administrative access via a direct request, as demonstrated by a request to ping.php.  Assigned (20121114)  None (candidate not yet proposed)    View
59363  CVE-2012-6120  Candidate  Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files.  Assigned (20121206)  None (candidate not yet proposed)    View
59619  CVE-2012-6376  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20121216)  None (candidate not yet proposed)    View

Page 18693 of 20943, showing 5 records out of 104715 total, starting on record 93461, ending on 93465

Actions