CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
49383 | CVE-2011-1471 | Candidate | Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (CPU consumption) via a malformed archive file that triggers errors in zip_fread function calls. | Assigned (20110319) | None (candidate not yet proposed) | View | |
49639 | CVE-2011-1727 | Candidate | Cross-site scripting (XSS) vulnerability in HP SiteScope 9.54, 10.13, 11.01, and 11.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to an "HTML injection" issue. | Assigned (20110419) | None (candidate not yet proposed) | View | |
49895 | CVE-2011-1983 | Candidate | Use-after-free vulnerability in Microsoft Office 2007 SP2 and SP3, Office 2010 Gold and SP1, and Office for Mac 2011 allows remote attackers to execute arbitrary code via a crafted Word document, aka "Word Use After Free Vulnerability." | Assigned (20110509) | None (candidate not yet proposed) | View | |
50151 | CVE-2011-2239 | Candidate | Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability, related to XMLSEQ_IMP_T. | Assigned (20110602) | None (candidate not yet proposed) | View | |
50407 | CVE-2011-2495 | Candidate | fs/proc/base.c in the Linux kernel before 2.6.39.4 does not properly restrict access to /proc/#####/io files, which allows local users to obtain sensitive I/O statistics by polling a file, as demonstrated by discovering the length of another user"s password. | Assigned (20110615) | None (candidate not yet proposed) | View |
Page 19008 of 20943, showing 5 records out of 104715 total, starting on record 95036, ending on 95040