CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52231  CVE-2011-4319  Candidate  Cross-site scripting (XSS) vulnerability in the i18n translations helper method in Ruby on Rails 3.0.x before 3.0.11 and 3.1.x before 3.1.2, and the rails_xss plugin in Ruby on Rails 2.3.x, allows remote attackers to inject arbitrary web script or HTML via vectors related to a translations string whose name ends with an "html" substring.  Assigned (20111104)  None (candidate not yet proposed)    View
52487  CVE-2011-4575  Candidate  Cross-site scripting (XSS) vulnerability in the JMX console in JBoss Enterprise Application Platform (EAP) before 5.2.0, Web Platform (EWP) before 5.2.0, BRMS Platform before 5.3.1, and SOA Platform before 5.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20111129)  None (candidate not yet proposed)    View
52743  CVE-2011-4831  Candidate  Directory traversal vulnerability in webFileBrowser.php in Web File Browser 0.4b14 allows remote authenticated users to read arbitrary files via a ..%2f (encoded dot dot) in the file parameter in a download action.  Assigned (20111214)  None (candidate not yet proposed)    View
52999  CVE-2011-5087  Candidate  Unspecified vulnerability in AdAstrA TRACE MODE Data Center allows remote attackers to read arbitrary files via unknown vectors, as demonstrated by the GLEG Agora SCADA+ Exploit Pack for Immunity CANVAS.  Assigned (20120418)  None (candidate not yet proposed)    View
53255  CVE-2012-0012  Candidate  Microsoft Internet Explorer 9 does not properly handle the creation and initialization of string objects, which allows remote attackers to read data from arbitrary process-memory locations via a crafted web site, aka "Null Byte Information Disclosure Vulnerability."  Assigned (20111109)  None (candidate not yet proposed)    View

Page 630 of 20943, showing 5 records out of 104715 total, starting on record 3146, ending on 3150

Actions