CVE List

Id CVE No. Status Description Phase Votes Comments Actions
49412  CVE-2011-1500  Candidate  PreferencesPithosDialog.py in Pithos 0.3.7 does not properly restrict permissions for the .config/pithos.ini file in a user"s home directory, which allows local users to obtain Pandora credentials by reading this file.  Assigned (20110321)  None (candidate not yet proposed)    View
49668  CVE-2011-1756  Candidate  modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.  Assigned (20110419)  None (candidate not yet proposed)    View
49924  CVE-2011-2012  Candidate  Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash."  Assigned (20110509)  None (candidate not yet proposed)    View
50180  CVE-2011-2268  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20110602)  None (candidate not yet proposed)    View
50436  CVE-2011-2524  Candidate  Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI.  Assigned (20110615)  None (candidate not yet proposed)    View

Page 392 of 20943, showing 5 records out of 104715 total, starting on record 1956, ending on 1960

Actions