CVE List

Id CVE No. Status Description Phase Votes Comments Actions
48900  CVE-2011-0988  Candidate  pure-ftpd 1.0.22, as used in SUSE Linux Enterprise Server 10 SP3 and SP4, and Enterprise Desktop 10 SP3 and SP4, when running OES Netware extensions, creates a world-writeable directory, which allows local users to overwrite arbitrary files and gain privileges via unspecified vectors.  Assigned (20110214)  None (candidate not yet proposed)    View
49156  CVE-2011-1244  Candidate  Microsoft Internet Explorer 6, 7, and 8 does not enforce intended domain restrictions on content access, which allows remote attackers to obtain sensitive information or conduct clickjacking attacks via a crafted web site, aka "Frame Tag Information Disclosure Vulnerability."  Assigned (20110304)  None (candidate not yet proposed)    View
49412  CVE-2011-1500  Candidate  PreferencesPithosDialog.py in Pithos 0.3.7 does not properly restrict permissions for the .config/pithos.ini file in a user"s home directory, which allows local users to obtain Pandora credentials by reading this file.  Assigned (20110321)  None (candidate not yet proposed)    View
49668  CVE-2011-1756  Candidate  modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.  Assigned (20110419)  None (candidate not yet proposed)    View
49924  CVE-2011-2012  Candidate  Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash."  Assigned (20110509)  None (candidate not yet proposed)    View

Page 387 of 20943, showing 5 records out of 104715 total, starting on record 1931, ending on 1935

Actions