CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52502  CVE-2011-4590  Candidate  The web services implementation in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3 does not properly consider the maintenance-mode state and account attributes during login attempts, which allows remote authenticated users to bypass intended access restrictions by connecting to a webservice server.  Assigned (20111129)  None (candidate not yet proposed)    View
52758  CVE-2011-4846  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20111215)  None (candidate not yet proposed)    View
53014  CVE-2011-5102  Candidate  The Investigative Reports web interface in the TRITON management console in Websense Web Security 7.1 before Hotfix 109, 7.1.1 before Hotfix 06, 7.5 before Hotfix 78, 7.5.1 before Hotfix 12, 7.6 before Hotfix 24, and 7.6.2 before Hotfix 12; Web Filter; Web Security Gateway; and Web Security Gateway Anywhere allows remote attackers to execute commands via unspecified vectors.  Assigned (20120823)  None (candidate not yet proposed)    View
53270  CVE-2012-0027  Candidate  The GOST ENGINE in OpenSSL before 1.0.0f does not properly handle invalid parameters for the GOST block cipher, which allows remote attackers to cause a denial of service (daemon crash) via crafted data from a TLS client.  Assigned (20111207)  None (candidate not yet proposed)    View
53526  CVE-2012-0283  Candidate  Cross-site scripting (XSS) vulnerability in the tpl_mediaFileList function in inc/template.php in DokuWiki before 2012-01-25b allows remote attackers to inject arbitrary web script or HTML via the ns parameter in a medialist action to lib/exe/ajax.php.  Assigned (20111230)  None (candidate not yet proposed)    View

Page 1820 of 20943, showing 5 records out of 104715 total, starting on record 9096, ending on 9100

Actions