CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51206  CVE-2011-3294  Candidate  Cross-site scripting (XSS) vulnerability in the login page in the administrative interface on Cisco TelePresence Video Communication Servers (VCS) with software before X7.0 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header, aka Bug ID CSCts80342.  Assigned (20110829)  None (candidate not yet proposed)    View
51462  CVE-2011-3550  Candidate  Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability, related to AWT.  Assigned (20110916)  None (candidate not yet proposed)    View
51718  CVE-2011-3806  Candidate  TCExam 11.1.015 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/code/tce_page_footer.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View
51974  CVE-2011-4062  Candidate  Buffer overflow in the kernel in FreeBSD 7.3 through 9.0-RC1 allows local users to cause a denial of service (panic) or possibly gain privileges via a bind system call with a long pathname for a UNIX socket.  Assigned (20111015)  None (candidate not yet proposed)    View
52230  CVE-2011-4318  Candidate  Dovecot 2.0.x before 2.0.16, when ssl or starttls is enabled and hostname is used to define the proxy destination, does not verify that the server hostname matches a domain name in the subject"s Common Name (CN) of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via a valid certificate for a different hostname.  Assigned (20111104)  None (candidate not yet proposed)    View

Page 554 of 20943, showing 5 records out of 104715 total, starting on record 2766, ending on 2770

Actions