CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
49412 | CVE-2011-1500 | Candidate | PreferencesPithosDialog.py in Pithos 0.3.7 does not properly restrict permissions for the .config/pithos.ini file in a user"s home directory, which allows local users to obtain Pandora credentials by reading this file. | Assigned (20110321) | None (candidate not yet proposed) | View | |
49668 | CVE-2011-1756 | Candidate | modules/xmpp/serv_xmpp.c in Citadel 7.86 and earlier does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. | Assigned (20110419) | None (candidate not yet proposed) | View | |
49924 | CVE-2011-2012 | Candidate | Microsoft Forefront Unified Access Gateway (UAG) 2010 Gold, Update 1, Update 2, and SP1 does not properly validate session cookies, which allows remote attackers to cause a denial of service (IIS outage) via unspecified network traffic, aka "Null Session Cookie Crash." | Assigned (20110509) | None (candidate not yet proposed) | View | |
50180 | CVE-2011-2268 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20110602) | None (candidate not yet proposed) | View | |
50436 | CVE-2011-2524 | Candidate | Directory traversal vulnerability in soup-uri.c in SoupServer in libsoup before 2.35.4 allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in a URI. | Assigned (20110615) | None (candidate not yet proposed) | View |
Page 392 of 20943, showing 5 records out of 104715 total, starting on record 1956, ending on 1960