CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51473  CVE-2011-3561  Candidate  Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, and JavaFX 2.0 allows remote attackers to affect confidentiality via unknown vectors related to Deployment.  Assigned (20110916)  None (candidate not yet proposed)    View
51729  CVE-2011-3817  Candidate  Website Baker 2.8.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/media/parameters.php and certain other files. NOTE: this might overlap CVE-2005-2436.  Assigned (20110923)  None (candidate not yet proposed)    View
51985  CVE-2011-4073  Candidate  Use-after-free vulnerability in the cryptographic helper handler functionality in Openswan 2.3.0 through 2.6.36 allows remote authenticated users to cause a denial of service (pluto IKE daemon crash) via vectors related to the (1) quick_outI1_continue and (2) quick_outI1 functions.  Assigned (20111018)  None (candidate not yet proposed)    View
52241  CVE-2011-4329  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter in a setup action to admin/company.php, or the PATH_INFO to (2) admin/security_other.php, (3) admin/events.php, or (4) admin/user.php.  Assigned (20111104)  None (candidate not yet proposed)    View
52497  CVE-2011-4585  Candidate  login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.  Assigned (20111129)  None (candidate not yet proposed)    View

Page 1413 of 20943, showing 5 records out of 104715 total, starting on record 7061, ending on 7065

Actions