CVE List

Id CVE No. Status Description Phase Votes Comments Actions
54249  CVE-2012-1006  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.0.14 and 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) lastName parameter to struts2-showcase/person/editPerson.action, or the (3) clientName parameter to struts2-rest-showcase/orders.  Assigned (20120206)  None (candidate not yet proposed)    View
54505  CVE-2012-1262  Candidate  Cross-site scripting (XSS) vulnerability in cgi-bin/mt/mt-wizard.cgi in Movable Type before 4.38, 5.0x before 5.07, and 5.1x before 5.13, when the product is incompletely installed, allows remote attackers to inject arbitrary web script or HTML via the dbuser parameter, a different vulnerability than CVE-2012-0318.  Assigned (20120222)  None (candidate not yet proposed)    View
54761  CVE-2012-1518  Candidate  VMware Workstation 8.x before 8.0.2, VMware Player 4.x before 4.0.2, VMware Fusion 4.x before 4.1.2, VMware ESXi 3.5 through 5.0, and VMware ESX 3.5 through 4.1 use an incorrect ACL for the VMware Tools folder, which allows guest OS users to gain guest OS privileges via unspecified vectors.  Assigned (20120308)  None (candidate not yet proposed)    View
55017  CVE-2012-1774  Candidate  Unspecified vulnerability in the Open URL feature in Gretech GOM Media Player before 2.1.39.5101 has unknown impact and attack vectors, a different vulnerability than CVE-2007-5779 and CVE-2012-1264.  Assigned (20120317)  None (candidate not yet proposed)    View
55273  CVE-2012-2030  Candidate  Adobe Shockwave Player before 11.6.5.635 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2029, CVE-2012-2031, CVE-2012-2032, and CVE-2012-2033.  Assigned (20120402)  None (candidate not yet proposed)    View

Page 19184 of 20943, showing 5 records out of 104715 total, starting on record 95916, ending on 95920

Actions