CVE List

Id CVE No. Status Description Phase Votes Comments Actions
48651  CVE-2011-0739  Candidate  The deliver function in the sendmail delivery agent (lib/mail/network/delivery_methods/sendmail.rb) in Ruby Mail gem 2.2.14 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in an e-mail address.  Assigned (20110201)  None (candidate not yet proposed)    View
48907  CVE-2011-0995  Candidate  The sqlite3-ruby gem in the rubygem-sqlite3 package before 1.2.4-0.5.1 in SUSE Linux Enterprise (SLE) 11 SP1 uses weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.  Assigned (20110214)  None (candidate not yet proposed)    View
49163  CVE-2011-1251  Candidate  Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, aka "DOM Manipulation Memory Corruption Vulnerability."  Assigned (20110304)  None (candidate not yet proposed)    View
49419  CVE-2011-1507  Candidate  Asterisk Open Source 1.4.x before 1.4.40.1, 1.6.1.x before 1.6.1.25, 1.6.2.x before 1.6.2.17.3, and 1.8.x before 1.8.3.3 and Asterisk Business Edition C.x.x before C.3.6.4 do not restrict the number of unauthenticated sessions to certain interfaces, which allows remote attackers to cause a denial of service (file descriptor exhaustion and disk space exhaustion) via a series of TCP connections.  Assigned (20110323)  None (candidate not yet proposed)    View
49675  CVE-2011-1763  Candidate  The get_free_port function in Xen allows local authenticated DomU users to cause a denial of service or possibly gain privileges via unspecified vectors involving a new event channel port.  Assigned (20110419)  None (candidate not yet proposed)    View

Page 945 of 20943, showing 5 records out of 104715 total, starting on record 4721, ending on 4725

Actions