CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51729  CVE-2011-3817  Candidate  Website Baker 2.8.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by admin/media/parameters.php and certain other files. NOTE: this might overlap CVE-2005-2436.  Assigned (20110923)  None (candidate not yet proposed)    View
51985  CVE-2011-4073  Candidate  Use-after-free vulnerability in the cryptographic helper handler functionality in Openswan 2.3.0 through 2.6.36 allows remote authenticated users to cause a denial of service (pluto IKE daemon crash) via vectors related to the (1) quick_outI1_continue and (2) quick_outI1 functions.  Assigned (20111018)  None (candidate not yet proposed)    View
52241  CVE-2011-4329  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter in a setup action to admin/company.php, or the PATH_INFO to (2) admin/security_other.php, (3) admin/events.php, or (4) admin/user.php.  Assigned (20111104)  None (candidate not yet proposed)    View
52497  CVE-2011-4585  Candidate  login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to obtain credentials by sniffing the network.  Assigned (20111129)  None (candidate not yet proposed)    View
52753  CVE-2011-4841  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20111215)  None (candidate not yet proposed)    View

Page 1422 of 20943, showing 5 records out of 104715 total, starting on record 7106, ending on 7110

Actions