CVE List

Id CVE No. Status Description Phase Votes Comments Actions
54295  CVE-2012-1052  Candidate  Buffer overflow in IvanView 1.2.15 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.  Assigned (20120213)  None (candidate not yet proposed)    View
54551  CVE-2012-1308  Candidate  Cross-site request forgery (CSRF) vulnerability in redpass.cgi in D-Link DSL-2640B Firmware EU_4.00 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter.  Assigned (20120227)  None (candidate not yet proposed)    View
54807  CVE-2012-1564  Candidate  Cross-site scripting (XSS) vulnerability in administration/create_album.php in YVS Image Gallery allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20120312)  None (candidate not yet proposed)    View
55063  CVE-2012-1820  Candidate  The bgp_capability_orf function in bgpd in Quagga 0.99.20.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) by leveraging a BGP peering relationship and sending a malformed Outbound Route Filtering (ORF) capability TLV in an OPEN message.  Assigned (20120321)  None (candidate not yet proposed)    View
55319  CVE-2012-2076  Candidate  Cross-site scripting (XSS) vulnerability in the administration forms in the ShareThis module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with administer sharethis permissions to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20120404)  None (candidate not yet proposed)    View

Page 1924 of 20943, showing 5 records out of 104715 total, starting on record 9616, ending on 9620

Actions