CVE List

Id CVE No. Status Description Phase Votes Comments Actions
50662  CVE-2011-2750  Candidate  NFRAgent.exe in Novell File Reporter 1.0.4.2 and earlier allows remote attackers to delete arbitrary files via a full pathname in an SRS OPERATION 4 CMD 5 request to /FSF/CMD.  Assigned (20110717)  None (candidate not yet proposed)    View
50918  CVE-2011-3006  Candidate  The MyAsUtil ActiveX control in MyAsUtil5.2.0.603.dll in McAfee SaaS Endpoint Protection 5.2.1 and earlier allows remote attackers to bypass the MyASUtil.SecureObjectFactory.CreateSecureObject domain execution policy using a cross-site scripting (XSS) attack, execute arbitrary code using the MyASUtil.InstallInfo.RunUserProgram function, and possibly conduct other unspecified attacks.  Assigned (20110802)  None (candidate not yet proposed)    View
51174  CVE-2011-3262  Candidate  tools/libxc/xc_dom_bzimageloader.c in Xen 3.2, 3.3, 4.0, and 4.1 allows local users to cause a denial of service (management software infinite loop and management domain resource consumption) via unspecified vectors related to "Lack of error checking in the decompression loop."  Assigned (20110819)  None (candidate not yet proposed)    View
51430  CVE-2011-3518  Candidate  Unspecified vulnerability in the Siebel Core - UIF Client component in Oracle Siebel CRM 8.0.0 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to User Interface.  Assigned (20110916)  None (candidate not yet proposed)    View
51686  CVE-2011-3774  Candidate  php Easy Survey Package (phpESP) 2.1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/landing.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View

Page 18943 of 20943, showing 5 records out of 104715 total, starting on record 94711, ending on 94715

Actions