CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52739  CVE-2011-4827  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in AutoSec Tools V-CMS 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) p parameter to redirect.php and (2) box parameter to includes/TrueColorPicker/index.php, which is not properly handled in includes/TrueColorPicker/class.TrueColorPicker.php.  Assigned (20111214)  None (candidate not yet proposed)    View
52995  CVE-2011-5083  Candidate  Unrestricted file upload vulnerability in inc/swf/swfupload.swf in Dotclear 2.3.1 and 2.4.2 allows remote attackers to execute arbitrary code by uploading a file with an executable PHP extension, then accessing it via a direct request to the file in an unspecified directory.  Assigned (20120319)  None (candidate not yet proposed)    View
53251  CVE-2012-0008  Candidate  Untrusted search path vulnerability in Microsoft Visual Studio 2008 SP1, 2010, and 2010 SP1 allows local users to gain privileges via a Trojan horse add-in in an unspecified directory, aka "Visual Studio Add-In Vulnerability."  Assigned (20111109)  None (candidate not yet proposed)    View
53507  CVE-2012-0264  Candidate  op5 Monitor and op5 Appliance before 5.5.0 do not properly manage session cookies, which allows remote attackers to have an unspecified impact via unspecified vectors.  Assigned (20111221)  None (candidate not yet proposed)    View
53763  CVE-2012-0520  Candidate  Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.2, and in Oracle Enterprise Manager Grid Control 10.2.0.5 and 11.1.0.1, allows remote attackers to affect integrity via unknown vectors related to Security Framework.  Assigned (20120111)  None (candidate not yet proposed)    View

Page 310 of 20943, showing 5 records out of 104715 total, starting on record 1546, ending on 1550

Actions