CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51730  CVE-2011-3818  Candidate  WordPress 2.9.2 and 3.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by wp-admin/includes/user.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View
51986  CVE-2011-4074  Candidate  Cross-site scripting (XSS) vulnerability in cmd.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via an _debug command.  Assigned (20111018)  None (candidate not yet proposed)    View
52242  CVE-2011-4330  Candidate  Stack-based buffer overflow in the hfs_mac2asc function in fs/hfs/trans.c in the Linux kernel 2.6 allows local users to cause a denial of service (crash) and possibly execute arbitrary code via an HFS image with a crafted len field.  Assigned (20111104)  None (candidate not yet proposed)    View
52498  CVE-2011-4586  Candidate  CRLF injection vulnerability in calendar/set.php in the Calendar subsystem in Moodle 1.9.x before 1.9.15, 2.0.x before 2.0.6, and 2.1.x before 2.1.3 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via unspecified vectors.  Assigned (20111129)  None (candidate not yet proposed)    View
52754  CVE-2011-4842  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20111215)  None (candidate not yet proposed)    View

Page 1501 of 20943, showing 5 records out of 104715 total, starting on record 7501, ending on 7505

Actions