CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52969  CVE-2011-5057  Candidate  Apache Struts 2.3.1.1 and earlier provides interfaces that do not properly restrict access to collections such as the session and request collections, which might allow remote attackers to modify run-time data values via a crafted parameter to an application that implements an affected interface, as demonstrated by the SessionAware, RequestAware, ApplicationAware, ServletRequestAware, ServletResponseAware, and ParameterAware interfaces. NOTE: the vendor disputes the significance of this report because of an "easy work-around in existing apps by configuring the interceptor."  Assigned (20120108)  None (candidate not yet proposed)    View
53225  CVE-2011-5313  Candidate  Multiple SQL injection vulnerabilities in includes/password.php in Redaxscript 0.3.2 allow remote attackers to execute arbitrary SQL commands via the (1) id or (2) password parameter to the password_reset program.  Assigned (20150101)  None (candidate not yet proposed)    View
53481  CVE-2012-0238  Candidate  Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via unspecified vectors.  Assigned (20111221)  None (candidate not yet proposed)    View
53737  CVE-2012-0494  Candidate  Unspecified vulnerability in the MySQL Server component in Oracle MySQL 5.5.x allows local users to affect availability via unknown vectors.  Assigned (20120111)  None (candidate not yet proposed)    View
53993  CVE-2012-0750  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20120118)  None (candidate not yet proposed)    View

Page 19183 of 20943, showing 5 records out of 104715 total, starting on record 95911, ending on 95915

Actions