CVE List

Id CVE No. Status Description Phase Votes Comments Actions
48363  CVE-2011-0451  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in (1) data/Smarty/templates/default/list.tpl and (2) data/Smarty/templates/default/campaign/bloc/cart_tag.tpl in EC-CUBE before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20110114)  None (candidate not yet proposed)    View
48619  CVE-2011-0707  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.  Assigned (20110131)  None (candidate not yet proposed)    View
48875  CVE-2011-0963  Candidate  The default configuration of the RADIUS authentication feature on the Cisco Network Admission Control (NAC) Guest Server with software before 2.0.3 allows remote attackers to bypass intended access restrictions and obtain network connectivity via unspecified vectors, aka Bug ID CSCtj66922.  Assigned (20110210)  None (candidate not yet proposed)    View
49131  CVE-2011-1219  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20110303)  None (candidate not yet proposed)    View
49387  CVE-2011-1475  Candidate  The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."  Assigned (20110321)  None (candidate not yet proposed)    View

Page 19328 of 20943, showing 5 records out of 104715 total, starting on record 96636, ending on 96640

Actions