CVE List

Id CVE No. Status Description Phase Votes Comments Actions
50413  CVE-2011-2501  Candidate  The png_format_buffer function in pngerror.c in libpng 1.0.x before 1.0.55, 1.2.x before 1.2.45, 1.4.x before 1.4.8, and 1.5.x before 1.5.4 allows remote attackers to cause a denial of service (application crash) via a crafted PNG image that triggers an out-of-bounds read during the copying of error-message data. NOTE: this vulnerability exists because of a CVE-2004-0421 regression. NOTE: this is called an off-by-one error by some sources.  Assigned (20110615)  None (candidate not yet proposed)    View
50669  CVE-2011-2757  Candidate  Directory traversal vulnerability in FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0.0.12 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the FILENAME parameter. NOTE: this might overlap the US-CERT VU#543310 issue.  Assigned (20110717)  None (candidate not yet proposed)    View
50925  CVE-2011-3013  Candidate  WebAdmin in the Mobility Pack before 1.2 in Novell Data Synchronizer 1.x through 1.1.2 build 428 supports weak SSL ciphers, which makes it easier for remote attackers to obtain access via a brute-force attack.  Assigned (20110809)  None (candidate not yet proposed)    View
51181  CVE-2011-3269  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20110825)  None (candidate not yet proposed)    View
51437  CVE-2011-3525  Candidate  Unspecified vulnerability in the Application Express component in Oracle Database Server 3.2 and 4.0 allows remote authenticated users to affect confidentiality, integrity, and availability, related to APEX developer user.  Assigned (20110916)  None (candidate not yet proposed)    View

Page 19508 of 20943, showing 5 records out of 104715 total, starting on record 97536, ending on 97540

Actions