CVE List

Id CVE No. Status Description Phase Votes Comments Actions
49421  CVE-2011-1509  Candidate  The encryptPassword function in Login.js in ManageEngine ServiceDesk Plus (SDP) 8012 and earlier uses a Caesar cipher for encryption of passwords in cookies, which makes it easier for remote attackers to obtain sensitive information by sniffing the network.  Assigned (20110323)  None (candidate not yet proposed)    View
49677  CVE-2011-1765  Candidate  Cross-site scripting (XSS) vulnerability in MediaWiki before 1.16.5, when Internet Explorer 6 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an uploaded file accessed with a dangerous extension such as .shtml at the end of the query string, in conjunction with a modified URI path that has a %2E sequence in place of the . (dot) character. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1578 and CVE-2011-1587.  Assigned (20110419)  None (candidate not yet proposed)    View
49933  CVE-2011-2021  Candidate  Session fixation vulnerability in TIBCO iProcess Engine before 11.1.3 and iProcess Workspace before 11.3.1 allows remote attackers to hijack web sessions via unspecified vectors.  Assigned (20110509)  None (candidate not yet proposed)    View
50189  CVE-2011-2277  Candidate  Unspecified vulnerability in the PeopleSoft Enterprise SCM component in Oracle PeopleSoft Products 9.0 Bundle #36 and 9.1 Bundle #13 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Purchasing.  Assigned (20110602)  None (candidate not yet proposed)    View
50445  CVE-2011-2533  Candidate  The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.  Assigned (20110622)  None (candidate not yet proposed)    View

Page 1104 of 20943, showing 5 records out of 104715 total, starting on record 5516, ending on 5520

Actions