CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
51972 | CVE-2011-4060 | Candidate | The runtime linker in QNX Neutrino RTOS 6.5.0 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environment variables when a program is spawned from a setuid program, which allows local users to overwrite files via a symlink attack. | Assigned (20111015) | None (candidate not yet proposed) | View | |
52228 | CVE-2011-4316 | Candidate | Red Hat Enterprise Virtualization Manager (RHEV-M) before 3.1, in certain unspecified conditions, does not lock the desktop screen between SPICE sessions, which allows local users with access to a virtual machine to gain access to other users" desktop sessions via unspecified vectors. | Assigned (20111104) | None (candidate not yet proposed) | View | |
52484 | CVE-2011-4572 | Candidate | Cross-site scripting (XSS) vulnerability in inc/tesmodrewite.php in CF Image Hosting Script 1.3.82, 1.4.1, and probably other versions before 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the q parameter. NOTE: this was originally reported as a file disclosure vulnerability, but this is likely inaccurate. | Assigned (20111128) | None (candidate not yet proposed) | View | |
52740 | CVE-2011-4828 | Candidate | Unrestricted file upload vulnerability in includes/inline_image_upload.php in AutoSec Tools V-CMS 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in temp/. | Assigned (20111214) | None (candidate not yet proposed) | View | |
52996 | CVE-2011-5084 | Candidate | Cross-site scripting (XSS) vulnerability in Movable Type 4.x before 4.36 and 5.x before 5.05 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20120402) | None (candidate not yet proposed) | View |
Page 394 of 20943, showing 5 records out of 104715 total, starting on record 1966, ending on 1970