CVE List

Id CVE No. Status Description Phase Votes Comments Actions
50438  CVE-2011-2526  Candidate  Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.19, when sendfile is enabled for the HTTP APR or HTTP NIO connector, does not validate certain request attributes, which allows local users to bypass intended file access restrictions or cause a denial of service (infinite loop or JVM crash) by leveraging an untrusted web application.  Assigned (20110615)  None (candidate not yet proposed)    View
50694  CVE-2011-2782  Candidate  The drag-and-drop implementation in Google Chrome before 13.0.782.107 on Linux does not properly enforce permissions for files, which allows user-assisted remote attackers to bypass intended access restrictions via unspecified vectors.  Assigned (20110720)  None (candidate not yet proposed)    View
50950  CVE-2011-3038  Candidate  Use-after-free vulnerability in Google Chrome before 17.0.963.65 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to multi-column handling.  Assigned (20110809)  None (candidate not yet proposed)    View
51206  CVE-2011-3294  Candidate  Cross-site scripting (XSS) vulnerability in the login page in the administrative interface on Cisco TelePresence Video Communication Servers (VCS) with software before X7.0 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header, aka Bug ID CSCts80342.  Assigned (20110829)  None (candidate not yet proposed)    View
51462  CVE-2011-3550  Candidate  Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to AWT.  Assigned (20110916)  None (candidate not yet proposed)    View

Page 549 of 20943, showing 5 records out of 104715 total, starting on record 2741, ending on 2745

Actions