CVE List

Id CVE No. Status Description Phase Votes Comments Actions
48646  CVE-2011-0734  Candidate  Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via an id parameter containing a JavaScript onLoad event handler for a BODY element, related to a "tag body" attack. NOTE: this was originally reported as affecting 9.0.1 CHF1 and earlier.  Assigned (20110201)  None (candidate not yet proposed)    View
48902  CVE-2011-0990  Candidate  Race condition in the FastCopy optimization in the Array.Copy method in metadata/icall.c in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to trigger a buffer overflow and modify internal data structures, and cause a denial of service (plugin crash) or corrupt the internal state of the security manager, via a crafted media file in which a thread makes a change after a type check but before a copy action.  Assigned (20110214)  None (candidate not yet proposed)    View
49158  CVE-2011-1246  Candidate  Microsoft Internet Explorer 8 does not properly handle content settings in HTTP responses, which allows remote web servers to obtain sensitive information from a different (1) domain or (2) zone via a crafted response, aka "MIME Sniffing Information Disclosure Vulnerability."  Assigned (20110304)  None (candidate not yet proposed)    View
49414  CVE-2011-1502  Candidate  Liferay Portal Community Edition (CE) 6.x before 6.0.6 GA, when Apache Tomcat is used, allows remote authenticated users to read arbitrary files via an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.  Assigned (20110321)  None (candidate not yet proposed)    View
49670  CVE-2011-1758  Candidate  The krb5_save_ccname_done function in providers/krb5/krb5_auth.c in System Security Services Daemon (SSSD) 1.5.x before 1.5.7, when automatic ticket renewal and offline authentication are configured, uses a pathname string as a password, which allows local users to bypass Kerberos authentication by listing the /tmp directory to obtain the pathname.  Assigned (20110419)  None (candidate not yet proposed)    View

Page 552 of 20943, showing 5 records out of 104715 total, starting on record 2756, ending on 2760

Actions