CVE List

Id CVE No. Status Description Phase Votes Comments Actions
55554  CVE-2012-2311  Candidate  sapi/cgi/cgi_main.c in PHP before 5.3.13 and 5.4.x before 5.4.3, when configured as a CGI script (aka php-cgi), does not properly handle query strings that contain a %3D sequence but no = (equals sign) character, which allows remote attackers to execute arbitrary code by placing command-line options in the query string, related to lack of skipping a certain php_getopt for the "d" case. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-1823.  Assigned (20120419)  None (candidate not yet proposed)    View
55810  CVE-2012-2567  Candidate  The Xelex MobileTrack application 2.3.7 and earlier for Android uses hardcoded credentials, which allows remote attackers to obtain sensitive information via an unencrypted (1) FTP or (2) HTTP session.  Assigned (20120509)  None (candidate not yet proposed)    View
56066  CVE-2012-2823  Candidate  Use-after-free vulnerability in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to SVG resources.  Assigned (20120519)  None (candidate not yet proposed)    View
56322  CVE-2012-3079  Candidate  Cisco IOS 12.2 allows remote attackers to cause a denial of service (CPU consumption) by establishing many IPv6 neighbors, aka Bug ID CSCtn78957.  Assigned (20120530)  None (candidate not yet proposed)    View
56578  CVE-2012-3335  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20120607)  None (candidate not yet proposed)    View

Page 843 of 20943, showing 5 records out of 104715 total, starting on record 4211, ending on 4215

Actions