CVE List

Id CVE No. Status Description Phase Votes Comments Actions
49397  CVE-2011-1485  Candidate  Race condition in the pkexec utility and polkitd daemon in PolicyKit (aka polkit) 0.96 allows local users to gain privileges by executing a setuid program from pkexec, related to the use of the effective user ID instead of the real user ID.  Assigned (20110321)  None (candidate not yet proposed)    View
49653  CVE-2011-1741  Candidate  Stack-based buffer overflow in ftserver.exe in the OpenText Hummingbird Client Connector, as used in the Indexing Server in EMC Documentum eRoom 7.x before 7.4.3.f and other products, allows remote attackers to execute arbitrary code by sending a crafted message over TCP.  Assigned (20110419)  None (candidate not yet proposed)    View
49909  CVE-2011-1997  Candidate  Microsoft Internet Explorer 6 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing a deleted object, aka "OnLoad Event Remote Code Execution Vulnerability."  Assigned (20110509)  None (candidate not yet proposed)    View
50165  CVE-2011-2253  Candidate  Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability, related to SYSDBA.  Assigned (20110602)  None (candidate not yet proposed)    View
50421  CVE-2011-2509  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Joomla! before 1.6.4 allow remote attackers to inject arbitrary web script or HTML via (1) the query string to the com_contact component, as demonstrated by the Itemid parameter to index.php; (2) the query string to the com_content component, as demonstrated by the filter_order parameter to index.php; (3) the query string to the com_newsfeeds component, as demonstrated by an arbitrary parameter to index.php; or (4) the option parameter in a reset.request action to index.php; and, when Internet Explorer or Konqueror is used, (5) allow remote attackers to inject arbitrary web script or HTML via the searchword parameter in a search action to index.php in the com_search component.  Assigned (20110615)  None (candidate not yet proposed)    View

Page 20136 of 20943, showing 5 records out of 104715 total, starting on record 100676, ending on 100680

Actions