CVE List

Id CVE No. Status Description Phase Votes Comments Actions
48392  CVE-2011-0480  Candidate  Multiple buffer overflows in vorbis_dec.c in the Vorbis decoder in FFmpeg, as used in Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344, allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly have unspecified other impact via a crafted WebM file, related to buffers for (1) the channel floor and (2) the channel residue.  Assigned (20110114)  None (candidate not yet proposed)    View
48648  CVE-2011-0736  Candidate  ** DISPUTED ** Adobe ColdFusion 9.0.1 CHF1 and earlier, when a web application is configured to use a DBMS, allows remote attackers to obtain potentially sensitive information about the database structure via an id=- query to a .cfm file. NOTE: the vendor disputes the significance of this issue because the Site-wide Error Handler and Debug Output Settings sections of the ColdFusion Lockdown guide explain the requirement for settings that prevent this information disclosure.  Assigned (20110201)  None (candidate not yet proposed)    View
48904  CVE-2011-0992  Candidate  Use-after-free vulnerability in Mono, when Moonlight 2.x before 2.4.1 or 3.x before 3.99.3 is used, allows remote attackers to cause a denial of service (plugin crash) or obtain sensitive information via vectors related to member data in a resurrected MonoThread instance.  Assigned (20110214)  None (candidate not yet proposed)    View
49160  CVE-2011-1248  Candidate  WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send exceptions, which allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted packets, related to unintended stack-frame values and buffer passing, aka "WINS Service Failed Response Vulnerability."  Assigned (20110304)  None (candidate not yet proposed)    View
49416  CVE-2011-1504  Candidate  Cross-site scripting (XSS) vulnerability in Liferay Portal Community Edition (CE) 5.x and 6.x before 6.0.6 GA allows remote authenticated users to inject arbitrary web script or HTML via a blog title.  Assigned (20110321)  None (candidate not yet proposed)    View

Page 719 of 20943, showing 5 records out of 104715 total, starting on record 3591, ending on 3595

Actions