CVE List

Id CVE No. Status Description Phase Votes Comments Actions
49383  CVE-2011-1471  Candidate  Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive file that triggers errors in zip_fread function calls.  Assigned (20110319)  None (candidate not yet proposed)    View
49639  CVE-2011-1727  Candidate  Cross-site scripting (XSS) vulnerability in HP SiteScope 9.54, 10.13, 11.01, and 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an "HTML injection" issue.  Assigned (20110419)  None (candidate not yet proposed)    View
49895  CVE-2011-1983  Candidate  Use-after-free vulnerability in Microsoft Office 2007 SP2 and SP3, Office 2010 Gold and SP1, and Office for Mac 2011 allows remote attackers to execute arbitrary code via a crafted Word document, aka "Word Use After Free Vulnerability."  Assigned (20110509)  None (candidate not yet proposed)    View
50151  CVE-2011-2239  Candidate  Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability, related to XMLSEQ_IMP_T.  Assigned (20110602)  None (candidate not yet proposed)    View
50407  CVE-2011-2495  Candidate  fs/proc/base.c in the Linux kernel before 2.6.39.4 does not properly restrict access to /proc/#####/io files, which allows local users to obtain sensitive I/O statistics by polling a file, as demonstrated by discovering the length of another user"s password.  Assigned (20110615)  None (candidate not yet proposed)    View

Page 19008 of 20943, showing 5 records out of 104715 total, starting on record 95036, ending on 95040

Actions