CVE List

Id CVE No. Status Description Phase Votes Comments Actions
54278  CVE-2012-1035  Candidate  AdaCore Ada Web Services (AWS) before 2.10.2 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.  Assigned (20120208)  None (candidate not yet proposed)    View
54534  CVE-2012-1291  Candidate  Unspecified vulnerability in the com.sap.aii.mdt.amt.web.AMTPageProcessor servlet in SAP NetWeaver 7.0 allows remote attackers to obtain sensitive information about the Adapter Monitor via unspecified vectors, possibly related to the EnableInvokerServletGlobally property in the servlet_jsp service.  Assigned (20120223)  None (candidate not yet proposed)    View
54790  CVE-2012-1547  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20120309)  None (candidate not yet proposed)    View
55046  CVE-2012-1803  Candidate  RuggedCom Rugged Operating System (ROS) 3.10.x and earlier has a factory account with a password derived from the MAC Address field in the banner, which makes it easier for remote attackers to obtain access by performing a calculation on this address value, and then establishing a (1) TELNET, (2) remote shell (aka rsh), or (3) serial-console session.  Assigned (20120321)  None (candidate not yet proposed)    View
55302  CVE-2012-2059  Candidate  Cross-site scripting (XSS) vulnerability in the ticketyboo News Ticker module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20120404)  None (candidate not yet proposed)    View

Page 552 of 20943, showing 5 records out of 104715 total, starting on record 2756, ending on 2760

Actions