CVE List

Id CVE No. Status Description Phase Votes Comments Actions
59129  CVE-2012-5886  Candidate  The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.36, 6.x before 6.0.36, and 7.x before 7.0.30 caches information about the authenticated user within the session state, which makes it easier for remote attackers to bypass authentication via vectors related to the session ID.  Assigned (20121117)  None (candidate not yet proposed)    View
59385  CVE-2012-6142  Candidate  Session::Cookie in the HTML::EP module 0.2011 for Perl does not properly use the Storable::thaw function, which allows remote attackers to execute arbitrary code via a crafted request, which is not properly handled when it is deserialized.  Assigned (20121206)  None (candidate not yet proposed)    View
59641  CVE-2012-6398  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20121216)  None (candidate not yet proposed)    View
59897  CVE-2012-6654  Candidate  Multiple SQL injection vulnerabilities in ZPanel 10.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) resetkey or (2) inConfEmail parameter to index.php, a different vulnerability than CVE-2012-5685.  Assigned (20140814)  None (candidate not yet proposed)    View
60153  CVE-2013-0206  Candidate  Unrestricted file upload vulnerability in the Live CSS module 6.x-2.x before 6.x-2.1 and 7.x-2.x before 7.x-2.7 for Drupal allows remote authenticated users with the "administer CSS" permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an unspecified directory.  Assigned (20121206)  None (candidate not yet proposed)    View

Page 20458 of 20943, showing 5 records out of 104715 total, starting on record 102286, ending on 102290

Actions