CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
55035 | CVE-2012-1792 | Candidate | Cross-site scripting (XSS) vulnerability in osCommerce/OM/Core/Site/Setup/Application/Install/RPC/DBCheck.php in OSCommerce Online Merchant 3.0.2, when the software is being installed, allows remote attackers to inject arbitrary web script or HTML via the name parameter to oscommerce/index.php, which is not properly handled in an error message. NOTE: this might not be a vulnerability, since the ability to access oscommerce/index.php during installation may already imply administrator privileges. | Assigned (20120319) | None (candidate not yet proposed) | View | |
55291 | CVE-2012-2048 | Candidate | Unspecified vulnerability in Adobe ColdFusion 10 and earlier allows attackers to cause a denial of service via unknown vectors. | Assigned (20120402) | None (candidate not yet proposed) | View | |
55547 | CVE-2012-2304 | Candidate | The Linkit module 7.x-2.x before 7.x-2.3 for Drupal, when using an entity access module, does not check permissions when searching for entities, which allows remote attackers to obtain sensitive information via unspecified vectors. | Assigned (20120419) | None (candidate not yet proposed) | View | |
55803 | CVE-2012-2560 | Candidate | Directory traversal vulnerability in WellinTech KingView 6.53 allows remote attackers to read arbitrary files via a crafted HTTP request to port 8001. | Assigned (20120509) | None (candidate not yet proposed) | View | |
56059 | CVE-2012-2816 | Candidate | Google Chrome before 20.0.1132.43 on Windows does not properly isolate sandboxed processes, which might allow remote attackers to cause a denial of service (process interference) via unspecified vectors. | Assigned (20120519) | None (candidate not yet proposed) | View |
Page 20591 of 20943, showing 5 records out of 104715 total, starting on record 102951, ending on 102955