CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47851  CVE-2010-5267  Candidate  Untrusted search path vulnerability in MunSoft Easy Office Recovery 1.1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .doc, .xls, or .ppt file. NOTE: some of these details are obtained from third party information.  Assigned (20120907)  None (candidate not yet proposed)    View
48107  CVE-2011-0195  Candidate  The generate-id XPath function in libxslt in Apple iOS 4.3.x before 4.3.2 allows remote attackers to obtain potentially sensitive information about heap memory addresses via a crafted web site. NOTE: this may overlap CVE-2011-1202.  Assigned (20101223)  None (candidate not yet proposed)    View
48363  CVE-2011-0451  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in (1) data/Smarty/templates/default/list.tpl and (2) data/Smarty/templates/default/campaign/bloc/cart_tag.tpl in EC-CUBE before 2.4.4 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20110114)  None (candidate not yet proposed)    View
48619  CVE-2011-0707  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Cgi/confirm.py in GNU Mailman 2.1.14 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) full name or (2) username field in a confirmation message.  Assigned (20110131)  None (candidate not yet proposed)    View
48875  CVE-2011-0963  Candidate  The default configuration of the RADIUS authentication feature on the Cisco Network Admission Control (NAC) Guest Server with software before 2.0.3 allows remote attackers to bypass intended access restrictions and obtain network connectivity via unspecified vectors, aka Bug ID CSCtj66922.  Assigned (20110210)  None (candidate not yet proposed)    View

Page 19339 of 20943, showing 5 records out of 104715 total, starting on record 96691, ending on 96695

Actions