CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
58595 | CVE-2012-5352 | Candidate | Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack." | Assigned (20121009) | None (candidate not yet proposed) | View | |
58851 | CVE-2012-5608 | Candidate | Cross-site scripting (XSS) vulnerability in apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via arbitrary POST parameters. | Assigned (20121024) | None (candidate not yet proposed) | View | |
59107 | CVE-2012-5864 | Candidate | The management web pages on the Sinapsi eSolar Light Photovoltaic System Monitor (aka Schneider Electric Ezylog photovoltaic SCADA management server), Sinapsi eSolar, and Sinapsi eSolar DUO with firmware before 2.0.2870_2.2.12 do not require authentication, which allows remote attackers to obtain administrative access via a direct request, as demonstrated by a request to ping.php. | Assigned (20121114) | None (candidate not yet proposed) | View | |
59363 | CVE-2012-6120 | Candidate | Red Hat OpenStack Essex and Folsom creates the /var/log/puppet directory with world-readable permissions, which allows local users to obtain sensitive information such as Puppet log files. | Assigned (20121206) | None (candidate not yet proposed) | View | |
59619 | CVE-2012-6376 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20121216) | None (candidate not yet proposed) | View |
Page 18693 of 20943, showing 5 records out of 104715 total, starting on record 93461, ending on 93465