CVE List

Id CVE No. Status Description Phase Votes Comments Actions
57602  CVE-2012-4359  Candidate  Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 do not validate the return value of the realloc function, which allows remote attackers to cause a denial of service (invalid 0x00 write operation and daemon crash) or possibly have unspecified other impact via a port-46824 TCP packet with a crafted negative integer after the opcode. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-4358.  Assigned (20120819)  None (candidate not yet proposed)    View
57858  CVE-2012-4615  Candidate  EMC Smarts Network Configuration Manager (NCM) before 9.1 uses a hardcoded encryption key for the storage of credentials, which allows local users to obtain sensitive information via unspecified vectors.  Assigned (20120824)  None (candidate not yet proposed)    View
58114  CVE-2012-4871  Candidate  Cross-site scripting (XSS) vulnerability in service/graph_html.php in the administrator panel in LiteSpeed Web Server 4.1.11 allows remote attackers to inject arbitrary web script or HTML via the gtitle parameter.  Assigned (20120906)  None (candidate not yet proposed)    View
58370  CVE-2012-5127  Candidate  Integer overflow in Google Chrome before 23.0.1271.64 allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted WebP image.  Assigned (20120924)  None (candidate not yet proposed)    View
58626  CVE-2012-5383  Candidate  ** DISPUTED ** Untrusted search path vulnerability in the installation functionality in Oracle MySQL 5.5.28, when installed in the top-level C: directory, might allow local users to gain privileges via a Trojan horse DLL in the "C:MySQLMySQL Server 5.5in" directory, which may be added to the PATH system environment variable by an administrator, as demonstrated by a Trojan horse wlbsctrl.dll file used by the "IKE and AuthIP IPsec Keying Modules" system service in Windows Vista SP1, Windows Server 2008 SP2, Windows 7 SP1, and Windows 8 Release Preview. NOTE: CVE disputes this issue because the unsafe PATH is established only by a separate administrative action that is not a default part of the MySQL installation.  Assigned (20121011)  None (candidate not yet proposed)    View

Page 234 of 20943, showing 5 records out of 104715 total, starting on record 1166, ending on 1170

Actions