CVE List

Id CVE No. Status Description Phase Votes Comments Actions
49129  CVE-2011-1217  Candidate  Buffer overflow in kpprzrdr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .prz attachment. NOTE: some of these details are obtained from third party information.  Assigned (20110303)  None (candidate not yet proposed)    View
49385  CVE-2011-1473  Candidate  ** DISPUTED ** OpenSSL before 0.9.8l, and 0.9.8m through 1.x, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-5094. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment.  Assigned (20110321)  None (candidate not yet proposed)    View
49641  CVE-2011-1729  Candidate  Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed GET_FILE message.  Assigned (20110419)  None (candidate not yet proposed)    View
49897  CVE-2011-1985  Candidate  win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application, aka "Win32k Null Pointer De-reference Vulnerability."  Assigned (20110509)  None (candidate not yet proposed)    View
50153  CVE-2011-2241  Candidate  Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 10.1.3.4.1 and 11.1.1.3 allows remote attackers to affect availability via unknown vectors related to Analytics Server.  Assigned (20110602)  None (candidate not yet proposed)    View

Page 19180 of 20943, showing 5 records out of 104715 total, starting on record 95896, ending on 95900

Actions