CVE List

Id CVE No. Status Description Phase Votes Comments Actions
59128  CVE-2012-5885  Candidate  The replay-countermeasure functionality in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 tracks cnonce (aka client nonce) values instead of nonce (aka server nonce) and nc (aka nonce-count) values, which makes it easier for remote attackers to bypass intended access restrictions by sniffing the network for valid requests, a different vulnerability than CVE-2011-1184.  Assigned (20121117)  None (candidate not yet proposed)    View
59384  CVE-2012-6141  Candidate  The App::Context module 0.01 through 0.968 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request to (1) App::Session::Cookie or (2) App::Session::HTMLHidden, which is not properly handled when it is deserialized.  Assigned (20121206)  None (candidate not yet proposed)    View
59640  CVE-2012-6397  Candidate  Cross-site scripting (XSS) vulnerability in Cisco WebEx Social (formerly Cisco Quad) allows remote attackers to inject arbitrary web script or HTML via a crafted RSS service link, aka Bug ID CSCub61977.  Assigned (20121216)  None (candidate not yet proposed)    View
59896  CVE-2012-6653  Candidate  Unspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified impact and attack vectors.  Assigned (20140806)  None (candidate not yet proposed)    View
60152  CVE-2013-0205  Candidate  Cross-site request forgery (CSRF) vulnerability in the RESTful Web Services (restws) module 7.x-1.x before 7.x-1.2 and 7.x-2.x before 7.x-2.0-alpha4 for Drupal allows remote attackers to hijack the authentication of arbitrary users via unknown vectors.  Assigned (20121206)  None (candidate not yet proposed)    View

Page 20363 of 20943, showing 5 records out of 104715 total, starting on record 101811, ending on 101815

Actions