CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
58083 | CVE-2012-4840 | Candidate | IBM Cognos Business Intelligence (BI) 8.4.1 before IF1, 10.1 before IF2, 10.1.1 before IF2, and 10.2 before IF1 allows remote attackers to conduct XPath injection attacks, and call XPath extension functions, via unspecified vectors. | Assigned (20120906) | None (candidate not yet proposed) | View | |
58339 | CVE-2012-5096 | Candidate | Unspecified vulnerability in the Server component in Oracle MySQL 5.5.28 and earlier allows remote authenticated users with Server Privileges to affect availability via unknown vectors. | Assigned (20120922) | None (candidate not yet proposed) | View | |
58595 | CVE-2012-5352 | Candidate | Java Open Single Sign-On Project Home (JOSSO) allows remote attackers to forge messages and bypass authentication via a SAML assertion that lacks a Signature element, aka a "Signature exclusion attack." | Assigned (20121009) | None (candidate not yet proposed) | View | |
58851 | CVE-2012-5608 | Candidate | Cross-site scripting (XSS) vulnerability in apps/user_webdavauth/settings.php in ownCloud 4.5.x before 4.5.2 allows remote attackers to inject arbitrary web script or HTML via arbitrary POST parameters. | Assigned (20121024) | None (candidate not yet proposed) | View | |
59107 | CVE-2012-5864 | Candidate | The management web pages on the Sinapsi eSolar Light Photovoltaic System Monitor (aka Schneider Electric Ezylog photovoltaic SCADA management server), Sinapsi eSolar, and Sinapsi eSolar DUO with firmware before 2.0.2870_2.2.12 do not require authentication, which allows remote attackers to obtain administrative access via a direct request, as demonstrated by a request to ping.php. | Assigned (20121114) | None (candidate not yet proposed) | View |
Page 18710 of 20943, showing 5 records out of 104715 total, starting on record 93546, ending on 93550