CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
54243 | CVE-2012-1000 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in LEPTON 1.1.3 and other versions before 1.1.4 allow remote attackers to inject arbitrary web script or HTML via the (1) message parameter to admins/login/forgot/index.php, or the (2) display_name or (3) email parameter to account/preferences.php. | Assigned (20120202) | None (candidate not yet proposed) | View | |
54499 | CVE-2012-1256 | Candidate | The single sign-on (SSO) implementation in EasyVista before 2010.1.1.89 allows remote attackers to bypass authentication via a modified url_account parameter, in conjunction with a valid login name in the SSPI_HEADER parameter, to index.php. | Assigned (20120221) | None (candidate not yet proposed) | View | |
54755 | CVE-2012-1512 | Candidate | Cross-site scripting (XSS) vulnerability in the internal browser in vSphere Client in VMware vSphere 4.1 before Update 2 and 5.0 before Update 1 allows remote attackers to inject arbitrary web script or HTML via a crafted log-file entry. | Assigned (20120308) | None (candidate not yet proposed) | View | |
55011 | CVE-2012-1768 | Candidate | Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.3.7 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-2012-3109. | Assigned (20120316) | None (candidate not yet proposed) | View | |
55267 | CVE-2012-2024 | Candidate | Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0780, CVE-2012-2023, CVE-2012-2025, and CVE-2012-2026. | Assigned (20120402) | None (candidate not yet proposed) | View |
Page 18739 of 20943, showing 5 records out of 104715 total, starting on record 93691, ending on 93695