CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
54295 | CVE-2012-1052 | Candidate | Buffer overflow in IvanView 1.2.15 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment. | Assigned (20120213) | None (candidate not yet proposed) | View | |
54551 | CVE-2012-1308 | Candidate | Cross-site request forgery (CSRF) vulnerability in redpass.cgi in D-Link DSL-2640B Firmware EU_4.00 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the sysPassword parameter. | Assigned (20120227) | None (candidate not yet proposed) | View | |
54807 | CVE-2012-1564 | Candidate | Cross-site scripting (XSS) vulnerability in administration/create_album.php in YVS Image Gallery allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20120312) | None (candidate not yet proposed) | View | |
55063 | CVE-2012-1820 | Candidate | The bgp_capability_orf function in bgpd in Quagga 0.99.20.1 and earlier allows remote attackers to cause a denial of service (assertion failure and daemon exit) by leveraging a BGP peering relationship and sending a malformed Outbound Route Filtering (ORF) capability TLV in an OPEN message. | Assigned (20120321) | None (candidate not yet proposed) | View | |
55319 | CVE-2012-2076 | Candidate | Cross-site scripting (XSS) vulnerability in the administration forms in the ShareThis module 7.x-2.x before 7.x-2.3 for Drupal allows remote authenticated users with administer sharethis permissions to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20120404) | None (candidate not yet proposed) | View |
Page 1924 of 20943, showing 5 records out of 104715 total, starting on record 9616, ending on 9620