CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
52994 | CVE-2011-5082 | Candidate | Cross-site scripting (XSS) vulnerability in the s2Member Pro plugin before 111220 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s2member_pro_authnet_checkout[coupon] parameter (aka Coupon Code field). | Assigned (20120319) | None (candidate not yet proposed) | View | |
53250 | CVE-2012-0007 | Candidate | The Microsoft Anti-Cross Site Scripting (AntiXSS) Library 3.x and 4.0 does not properly evaluate characters after the detection of a Cascading Style Sheets (CSS) escaped character, which allows remote attackers to conduct cross-site scripting (XSS) attacks via HTML input, aka "AntiXSS Library Bypass Vulnerability." | Assigned (20111109) | None (candidate not yet proposed) | View | |
53506 | CVE-2012-0263 | Candidate | monitor/index.php in op5 Monitor and op5 Appliance before 5.5.1 allows remote authenticated users to obtain sensitive information such as database and user credentials via error messages that are triggered by (1) a malformed hoststatustypes parameter to status/service/all or (2) a crafted request to config. | Assigned (20111221) | None (candidate not yet proposed) | View | |
53762 | CVE-2012-0519 | Candidate | Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.2.0.2, when running on Windows, allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. | Assigned (20120111) | None (candidate not yet proposed) | View | |
54018 | CVE-2012-0775 | Candidate | The JavaScript implementation in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors. | Assigned (20120118) | None (candidate not yet proposed) | View |
Page 841 of 20943, showing 5 records out of 104715 total, starting on record 4201, ending on 4205