CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
48360 | CVE-2011-0448 | Candidate | Ruby on Rails 3.0.x before 3.0.4 does not ensure that arguments to the limit function specify integer values, which makes it easier for remote attackers to conduct SQL injection attacks via a non-numeric argument. | Assigned (20110113) | None (candidate not yet proposed) | View | |
48616 | CVE-2011-0704 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20110131) | None (candidate not yet proposed) | View | |
48872 | CVE-2011-0960 | Candidate | Multiple SQL injection vulnerabilities in Cisco Unified Operations Manager (CUOM) before 8.6 allow remote attackers to execute arbitrary SQL commands via (1) the CCMs parameter to iptm/PRTestCreation.do or (2) the ccm parameter to iptm/TelePresenceReportAction.do, aka Bug ID CSCtn61716. | Assigned (20110210) | None (candidate not yet proposed) | View | |
49128 | CVE-2011-1216 | Candidate | Stack-based buffer overflow in assr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via crafted tag data in an Applix spreadsheet attachment, aka SPR PRAD8823A7. | Assigned (20110303) | None (candidate not yet proposed) | View | |
49384 | CVE-2011-1472 | Candidate | The Nokia E75 phone with firmware before 211.12.01 allows physically proximate attackers to bypass the Device Lock code by entering an unspecified button sequence at boot time. | Assigned (20110321) | None (candidate not yet proposed) | View |
Page 19120 of 20943, showing 5 records out of 104715 total, starting on record 95596, ending on 95600