CVE List

Id CVE No. Status Description Phase Votes Comments Actions
58879  CVE-2012-5636  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20121024)  None (candidate not yet proposed)    View
59135  CVE-2012-5892  Candidate  Havalite CMS 1.1.0 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the configuration database via a direct request for data/havalite.db3.  Assigned (20121117)  None (candidate not yet proposed)    View
59391  CVE-2012-6148  Candidate  Cross-site scripting (XSS) vulnerability in the function menu API in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20121206)  None (candidate not yet proposed)    View
59647  CVE-2012-6404  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20121216)  None (candidate not yet proposed)    View
59903  CVE-2012-6660  Candidate  GE Healthcare Precision MPi has a password of (1) orion for the serviceapp user, (2) orion for the clinical operator user, and (3) PlatinumOne for the administrator user, which has unspecified impact and attack vectors. NOTE: it is not clear whether these passwords are default, hardcoded, or dependent on another system or product that requires a fixed value.  Assigned (20140929)  None (candidate not yet proposed)    View

Page 20328 of 20943, showing 5 records out of 104715 total, starting on record 101636, ending on 101640

Actions