CVE List

Id CVE No. Status Description Phase Votes Comments Actions
55546  CVE-2012-2303  Candidate  The Spaces module 6.x-3.x before 6.x-3.4 for Drupal does not enforce permissions on non-object pages, which allows remote attackers to obtain sensitive information and possibly have other impacts via unspecified vectors to the (1) Spaces or (2) Spaces OG module.  Assigned (20120419)  None (candidate not yet proposed)    View
55802  CVE-2012-2559  Candidate  WellinTech KingHistorian 3.0 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer write) via a crafted packet to TCP port 5678.  Assigned (20120509)  None (candidate not yet proposed)    View
56058  CVE-2012-2815  Candidate  Google Chrome before 20.0.1132.43 allows remote attackers to obtain potentially sensitive information from a fragment identifier by leveraging access to an IFRAME element associated with a different domain.  Assigned (20120519)  None (candidate not yet proposed)    View
56314  CVE-2012-3071  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20120530)  None (candidate not yet proposed)    View
56570  CVE-2012-3327  Candidate  Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 6.2 through 7.5, Maximo Asset Management Essentials 6.2 through 7.5, Tivoli Asset Management for IT 6.2 through 7.2, Tivoli Service Request Manager 7.1 and 7.2, Maximo Service Desk 6.2, Change and Configuration Management Database (CCMDB) 7.1 and 7.2, and SmartCloud Control Desk 7.5 allows remote attackers to inject arbitrary web script or HTML via vectors related to a login action.  Assigned (20120607)  None (candidate not yet proposed)    View

Page 20535 of 20943, showing 5 records out of 104715 total, starting on record 102671, ending on 102675

Actions