CVE List

Id CVE No. Status Description Phase Votes Comments Actions
29577  CVE-2007-6220  Candidate  typespeed before 0.6.4 allows remote attackers to cause a denial of service (application crash) via unspecified network behavior that triggers a divide-by-zero error.  Assigned (20071204)  None (candidate not yet proposed)    View
64140  CVE-2013-4193  Candidate  typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL.  Assigned (20130612)  None (candidate not yet proposed)    View
35022  CVE-2008-4905  Candidate  Typo 5.1.3 and earlier uses a hard-coded salt for calculating password hashes, which makes it easier for attackers to guess passwords via a brute force attack.  Assigned (20081103)  None (candidate not yet proposed)    View
16431  CVE-2006-0327  Candidate  TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails.  Assigned (20060120)  None (candidate not yet proposed)    View
16079  CVE-2005-4875  Candidate  TYPO3 3.8.0 and earlier allows remote attackers to obtain sensitive information via a direct request to misc/phpcheck/, which invokes the phpinfo function and prints values of unspecified environment variables.  Assigned (20080519)  None (candidate not yet proposed)    View

Page 18596 of 20943, showing 5 records out of 104715 total, starting on record 92976, ending on 92980

Actions