CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52498  CVE-2011-4586  Candidate  CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.  Assigned (20111129)  None (candidate not yet proposed)    View
52754  CVE-2011-4842  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20111215)  None (candidate not yet proposed)    View
53010  CVE-2011-5098  Candidate  chef-server-api/app/controllers/clients.rb in Chef Server in Chef before 0.9.20, and 0.10.x before 0.10.6, does not require administrative privileges for creating admin clients, which allows remote authenticated users to bypass intended access restrictions by leveraging read permission for the validation key and executing a knife client create command with the --admin option.  Assigned (20120808)  None (candidate not yet proposed)    View
53266  CVE-2012-0023  Candidate  Double free vulnerability in the get_chunk_header function in modules/demux/ty.c in VideoLAN VLC media player 0.9.0 through 1.1.12 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TiVo (TY) file.  Assigned (20111207)  None (candidate not yet proposed)    View
53522  CVE-2012-0279  Candidate  Quest Toad for Data Analysts 3.0.1 uses weak permissions (Everyone: Full Control) for the %COMMONPROGRAMFILES%Quest Shared directory, which allows local users to gain privileges via a Trojan horse file.  Assigned (20111230)  None (candidate not yet proposed)    View

Page 1491 of 20943, showing 5 records out of 104715 total, starting on record 7451, ending on 7455

Actions