CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
76335 | CVE-2014-9034 | Candidate | wp-includes/class-phpass.php in WordPress before 3.7.5, 3.8.x before 3.8.5, 3.9.x before 3.9.3, and 4.x before 4.0.1 allows remote attackers to cause a denial of service (CPU consumption) via a long password that is improperly handled during hashing, a similar issue to CVE-2014-9016. | Assigned (20141120) | None (candidate not yet proposed) | View | |
62120 | CVE-2013-2173 | Candidate | wp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of service (CPU consumption) via a crafted value of a certain wp-postpass cookie. | Assigned (20130219) | None (candidate not yet proposed) | View | |
47880 | CVE-2010-5296 | Candidate | wp-includes/capabilities.php in WordPress before 3.0.2, when a Multisite configuration is used, does not require the Super Admin role for the delete_users capability, which allows remote authenticated administrators to bypass intended access restrictions via a delete action. | Assigned (20140120) | None (candidate not yet proposed) | View | |
41605 | CVE-2009-4170 | Candidate | WP-Cumulus Plug-in 1.20 for WordPress, and possibly other versions, allows remote attackers to obtain sensitive information via a crafted request to wp-cumulus.php, probably without parameters, which reveals the installation path in an error message. | Assigned (20091202) | None (candidate not yet proposed) | View | |
55647 | CVE-2012-2404 | Candidate | wp-comments-post.php in WordPress before 3.3.2 supports offsite redirects, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via unspecified vectors. | Assigned (20120421) | None (candidate not yet proposed) | View |
Page 136 of 20943, showing 5 records out of 104715 total, starting on record 676, ending on 680