CVE List

Id CVE No. Status Description Phase Votes Comments Actions
49385  CVE-2011-1473  Candidate  ** DISPUTED ** OpenSSL before 0.9.8l, and 0.9.8m through 1.x, does not properly restrict client-initiated renegotiation within the SSL and TLS protocols, which might make it easier for remote attackers to cause a denial of service (CPU consumption) by performing many renegotiations within a single connection, a different vulnerability than CVE-2011-5094. NOTE: it can also be argued that it is the responsibility of server deployments, not a security library, to prevent or limit renegotiation when it is inappropriate within a specific environment.  Assigned (20110321)  None (candidate not yet proposed)    View
49641  CVE-2011-1729  Candidate  Stack-based buffer overflow in OmniInet.exe in the Backup Client Service in HP OpenView Storage Data Protector 6.00, 6.10, and 6.11 allows remote attackers to execute arbitrary code via a malformed GET_FILE message.  Assigned (20110419)  None (candidate not yet proposed)    View
49897  CVE-2011-1985  Candidate  win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not properly validate user-mode input, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a crafted application, aka "Win32k Null Pointer De-reference Vulnerability."  Assigned (20110509)  None (candidate not yet proposed)    View
50153  CVE-2011-2241  Candidate  Unspecified vulnerability in the Oracle Business Intelligence Enterprise Edition component in Oracle Fusion Middleware 10.1.3.4.1 and 11.1.1.3 allows remote attackers to affect availability via unknown vectors related to Analytics Server.  Assigned (20110602)  None (candidate not yet proposed)    View
50409  CVE-2011-2497  Candidate  Integer underflow in the l2cap_config_req function in net/bluetooth/l2cap_core.c in the Linux kernel before 3.0 allows remote attackers to cause a denial of service (heap memory corruption) or possibly have unspecified other impact via a small command-size value within the command header of a Logical Link Control and Adaptation Protocol (L2CAP) configuration request, leading to a buffer overflow.  Assigned (20110615)  None (candidate not yet proposed)    View

Page 19198 of 20943, showing 5 records out of 104715 total, starting on record 95986, ending on 95990

Actions