CVE List

Id CVE No. Status Description Phase Votes Comments Actions
48360  CVE-2011-0448  Candidate  Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument.  Assigned (20110113)  None (candidate not yet proposed)    View
48616  CVE-2011-0704  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20110131)  None (candidate not yet proposed)    View
48872  CVE-2011-0960  Candidate  Multiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to execute arbitrary SQL commands via (1) the CCMs parameter to iptm/PRTestCreation.do or (2) the ccm parameter to iptm/TelePresenceReportAction.do, aka Bug ID CSCtn61716.  Assigned (20110210)  None (candidate not yet proposed)    View
49128  CVE-2011-1216  Candidate  Stack-based buffer overflow in assr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via crafted tag data in an Applix spreadsheet attachment, aka SPR PRAD8823A7.  Assigned (20110303)  None (candidate not yet proposed)    View
49384  CVE-2011-1472  Candidate  The Nokia E75 phone with firmware before 211.12.01 allows physically proximate attackers to bypass the Device Lock code by entering an unspecified button sequence at boot time.  Assigned (20110321)  None (candidate not yet proposed)    View

Page 19100 of 20943, showing 5 records out of 104715 total, starting on record 95496, ending on 95500

Actions