CVE List

Id CVE No. Status Description Phase Votes Comments Actions
76335  CVE-2014-9034  Candidate  wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016.  Assigned (20141120)  None (candidate not yet proposed)    View
62120  CVE-2013-2173  Candidate  wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie.  Assigned (20130219)  None (candidate not yet proposed)    View
47880  CVE-2010-5296  Candidate  wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action.  Assigned (20140120)  None (candidate not yet proposed)    View
41605  CVE-2009-4170  Candidate  WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to wp-cumulus.php, probably without parameters, which reveals the installation path in an error message.  Assigned (20091202)  None (candidate not yet proposed)    View
55647  CVE-2012-2404  Candidate  wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors.  Assigned (20120421)  None (candidate not yet proposed)    View

Page 136 of 20943, showing 5 records out of 104715 total, starting on record 676, ending on 680

Actions