CVE List

Id CVE No. Status Description Phase Votes Comments Actions
48640  CVE-2011-0728  Candidate  Cross-site scripting (XSS) vulnerability in templatefunctions.py in Loggerhead before 1.18.1 allows remote authenticated users to inject arbitrary web script or HTML via a filename, which is not properly handled in a revision view.  Assigned (20110201)  None (candidate not yet proposed)    View
48896  CVE-2011-0984  Candidate  Google Chrome before 9.0.597.94 does not properly handle plug-ins, which allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors.  Assigned (20110210)  None (candidate not yet proposed)    View
49152  CVE-2011-1240  Candidate  Use-after-free vulnerability in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, R2, and R2 SP1, and Windows 7 Gold and SP1 allows local users to gain privileges via a crafted application that leverages incorrect driver object management, a different vulnerability than other "Vulnerability Type 1" CVEs listed in MS11-034, aka "Win32k Use After Free Vulnerability."  Assigned (20110304)  None (candidate not yet proposed)    View
49408  CVE-2011-1496  Candidate  tmux 1.3 and 1.4 does not properly drop group privileges, which allows local users to gain utmp group privileges via a filename to the -S command-line option.  Assigned (20110321)  None (candidate not yet proposed)    View
49664  CVE-2011-1752  Candidate  The mod_dav_svn module for the Apache HTTP Server, as distributed in Apache Subversion before 1.6.17, allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a request for a baselined WebDAV resource, as exploited in the wild in May 2011.  Assigned (20110419)  None (candidate not yet proposed)    View

Page 678 of 20943, showing 5 records out of 104715 total, starting on record 3386, ending on 3390

Actions