CVE List

Id CVE No. Status Description Phase Votes Comments Actions
58135  CVE-2012-4892  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS 2012-03.08 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title_en, (2) summary_en, or (3) body_en parameter in a submitnews action to the news module, a different vulnerability than CVE-2012-4890. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20120910)  None (candidate not yet proposed)    View
58391  CVE-2012-5148  Candidate  The hyphenation functionality in Google Chrome before 24.0.1312.52 does not properly validate file names, which has unspecified impact and attack vectors.  Assigned (20120924)  None (candidate not yet proposed)    View
58647  CVE-2012-5404  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20121017)  None (candidate not yet proposed)    View
58903  CVE-2012-5660  Candidate  abrt-action-install-debuginfo in Automatic Bug Reporting Tool (ABRT) 2.0.9 and earlier allows local users to set world-writable permissions for arbitrary files and possibly gain privileges via a symlink attack on "the directories used to store information about crashes."  Assigned (20121024)  None (candidate not yet proposed)    View
59159  CVE-2012-5916  Candidate  Neocrome Seditio build 161 allows remote attackers to obtain sensitive information via a direct request to (1) docs/new/seditio-createnew-160.sql, (2) docs/upgrade/sedito_convert_to_utf8.optional.sql, or (3) system/install/install.parser.sql.  Assigned (20121117)  None (candidate not yet proposed)    View

Page 1927 of 20943, showing 5 records out of 104715 total, starting on record 9631, ending on 9635

Actions