CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
52480 | CVE-2011-4568 | Candidate | Cross-site scripting (XSS) vulnerability in view/frontend-head.php in the Flowplayer plugin before 1.2.12 for WordPress allows remote attackers to inject arbitrary web script or HTML via the URI. | Assigned (20111128) | None (candidate not yet proposed) | View | |
52736 | CVE-2011-4824 | Candidate | SQL injection vulnerability in auth_login.php in Cacti before 0.8.7h allows remote attackers to execute arbitrary SQL commands via the login_username parameter. | Assigned (20111214) | None (candidate not yet proposed) | View | |
52992 | CVE-2011-5080 | Candidate | Cross-site scripting (XSS) vulnerability in lib/class.tx_jftcaforms_tceFunc.php in the Additional TCA Forms (jftcaforms) extension before 0.2.1 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20120214) | None (candidate not yet proposed) | View | |
53248 | CVE-2012-0005 | Candidate | The Client/Server Run-time Subsystem (aka CSRSS) in the Win32 subsystem in Microsoft Windows XP SP2 and SP3, Server 2003 SP2, Vista SP2, and Server 2008 SP2, when a Chinese, Japanese, or Korean system locale is used, can access uninitialized memory during the processing of Unicode characters, which allows local users to gain privileges via a crafted application, aka "CSRSS Elevation of Privilege Vulnerability." | Assigned (20111109) | None (candidate not yet proposed) | View | |
53504 | CVE-2012-0261 | Candidate | license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the timestamp parameter for an install action. | Assigned (20111221) | None (candidate not yet proposed) | View |
Page 681 of 20943, showing 5 records out of 104715 total, starting on record 3401, ending on 3405