CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
48362 | CVE-2011-0450 | Candidate | The downloads manager in Opera before 11.01 on Windows does not properly determine the pathname of the filesystem-viewing application, which allows user-assisted remote attackers to execute arbitrary code via a crafted web site that hosts an executable file. | Assigned (20110114) | None (candidate not yet proposed) | View | |
48618 | CVE-2011-0706 | Candidate | The JNLPClassLoader class in IcedTea-Web before 1.0.1, as used in OpenJDK Runtime Environment 1.6.0, allows remote attackers to gain privileges via unknown vectors related to multiple signers and the assignment of "an inappropriate security descriptor." | Assigned (20110131) | None (candidate not yet proposed) | View | |
48874 | CVE-2011-0962 | Candidate | Cross-site scripting (XSS) vulnerability in CSCOnm/servlet/com.cisco.nm.help.ServerHelpEngine in the Common Services Device Center in Cisco Unified Operations Manager (CUOM) before 8.6 allows remote attackers to inject arbitrary web script or HTML via the tag parameter, aka Bug ID CSCto12712. | Assigned (20110210) | None (candidate not yet proposed) | View | |
49130 | CVE-2011-1218 | Candidate | Buffer overflow in kvarcve.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers to execute arbitrary code via a crafted .zip attachment, aka SPR PRAD8E3NSP. NOTE: some of these details are obtained from third party information. | Assigned (20110303) | None (candidate not yet proposed) | View | |
49386 | CVE-2011-1474 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20110321) | None (candidate not yet proposed) | View |
Page 19260 of 20943, showing 5 records out of 104715 total, starting on record 96296, ending on 96300