CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52994  CVE-2011-5082  Candidate  Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field).  Assigned (20120319)  None (candidate not yet proposed)    View
53250  CVE-2012-0007  Candidate  The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the detection of a Cascading Style Sheets (CSS) escaped character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML input, aka "AntiXSS Library Bypass Vulnerability."  Assigned (20111109)  None (candidate not yet proposed)    View
53506  CVE-2012-0263  Candidate  monitor/index.php in op5 Monitor and op5 Appliance before 5.5.1 allows remote authenticated users to obtain sensitive information such as database and user credentials via error messages that are triggered by (1) a malformed hoststatustypes parameter to status/service/all or (2) a crafted request to config.  Assigned (20111221)  None (candidate not yet proposed)    View
53762  CVE-2012-0519  Candidate  Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.2.0.2, when running on Windows, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.  Assigned (20120111)  None (candidate not yet proposed)    View
54018  CVE-2012-0775  Candidate  The JavaScript implementation in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.  Assigned (20120118)  None (candidate not yet proposed)    View

Page 841 of 20943, showing 5 records out of 104715 total, starting on record 4201, ending on 4205

Actions