CVE List

Id CVE No. Status Description Phase Votes Comments Actions
49158  CVE-2011-1246  Candidate  Microsoft Internet Explorer 8 does not properly handle content settings in HTTP responses, which allows remote web servers to obtain sensitive information from a different (1) domain or (2) zone via a crafted response, aka "MIME Sniffing Information Disclosure Vulnerability."  Assigned (20110304)  None (candidate not yet proposed)    View
49414  CVE-2011-1502  Candidate  Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.  Assigned (20110321)  None (candidate not yet proposed)    View
49670  CVE-2011-1758  Candidate  The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.  Assigned (20110419)  None (candidate not yet proposed)    View
49926  CVE-2011-2014  Candidate  The LDAP over SSL (aka LDAPS) implementation in Active Directory, Active Directory Application Mode (ADAM), and Active Directory Lightweight Directory Service (AD LDS) in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 does not examine Certificate Revocation Lists (CRLs), which allows remote authenticated users to bypass intended certificate restrictions and access Active Directory resources by leveraging a revoked X.509 certificate for a domain account, aka "LDAPS Authentication Bypass Vulnerability."  Assigned (20110509)  None (candidate not yet proposed)    View
50182  CVE-2011-2270  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20110602)  None (candidate not yet proposed)    View

Page 548 of 20943, showing 5 records out of 104715 total, starting on record 2736, ending on 2740

Actions