CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51461  CVE-2011-3549  Candidate  Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via unknown vectors related to Swing.  Assigned (20110916)  None (candidate not yet proposed)    View
51717  CVE-2011-3805  Candidate  TaskFreak! multi-mysql-0.6 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by include/language/zh/register_info.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View
51973  CVE-2011-4061  Candidate  Multiple untrusted search path vulnerabilities in (1) db2rspgn and (2) kbbacf1 in IBM DB2 Express Edition 9.7, as used in the IBM Tivoli Monitoring for Databases: DB2 Agent, allow local users to gain privileges via a Trojan horse libkbb.so in the current working directory, related to the DT_RPATH ELF header.  Assigned (20111015)  None (candidate not yet proposed)    View
52229  CVE-2011-4317  Candidate  The mod_proxy module in the Apache HTTP Server 1.3.x through 1.3.42, 2.0.x through 2.0.64, and 2.2.x through 2.2.21, when the Revision 1179239 patch is in place, does not properly interact with use of (1) RewriteRule and (2) ProxyPassMatch pattern matches for configuration of a reverse proxy, which allows remote attackers to send requests to intranet servers via a malformed URI containing an @ (at sign) character and a : (colon) character in invalid positions. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-3368.  Assigned (20111104)  None (candidate not yet proposed)    View
52485  CVE-2011-4573  Candidate  Red Hat JBoss Operations Network (JON) before 2.4.2 does not properly enforce "modify resource" permissions for remote authenticated users when deleting a plug-in configuration update from the group connection properties history, which prevents such activities from being recorded in the audit trail.  Assigned (20111129)  None (candidate not yet proposed)    View

Page 469 of 20943, showing 5 records out of 104715 total, starting on record 2341, ending on 2345

Actions