CVE List

Id CVE No. Status Description Phase Votes Comments Actions
59132  CVE-2012-5889  Candidate  Cross-site scripting (XSS) vulnerability in the powermail extension before 1.6.5 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20121117)  None (candidate not yet proposed)    View
59388  CVE-2012-6145  Candidate  Cross-site scripting (XSS) vulnerability in the Backend History module in TYPO3 4.5.x before 4.5.21, 4.6.x before 4.6.14, and 4.7.x before 4.7.6 allows remote authenticated backend users to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20121206)  None (candidate not yet proposed)    View
59644  CVE-2012-6401  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20121216)  None (candidate not yet proposed)    View
59900  CVE-2012-6657  Candidate  The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.  Assigned (20140915)  None (candidate not yet proposed)    View
60156  CVE-2013-0209  Candidate  lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for requests to database-migration functions, which allows remote attackers to conduct eval injection and SQL injection attacks via crafted parameters, as demonstrated by an eval injection attack against the core_drop_meta_for_table function, leading to execution of arbitrary Perl code.  Assigned (20121206)  None (candidate not yet proposed)    View

Page 20671 of 20943, showing 5 records out of 104715 total, starting on record 103351, ending on 103355

Actions