CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
29577 | CVE-2007-6220 | Candidate | typespeed before 0.6.4 allows remote attackers to cause a denial of service (application crash) via unspecified network behavior that triggers a divide-by-zero error. | Assigned (20071204) | None (candidate not yet proposed) | View | |
64140 | CVE-2013-4193 | Candidate | typeswidget.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 does not properly enforce the immutable setting on unspecified content edit forms, which allows remote attackers to hide fields on the forms via a crafted URL. | Assigned (20130612) | None (candidate not yet proposed) | View | |
35022 | CVE-2008-4905 | Candidate | Typo 5.1.3 and earlier uses a hard-coded salt for calculating password hashes, which makes it easier for attackers to guess passwords via a brute force attack. | Assigned (20081103) | None (candidate not yet proposed) | View | |
16431 | CVE-2006-0327 | Candidate | TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly define a variable and reveal the path in an error message when a require function call fails. | Assigned (20060120) | None (candidate not yet proposed) | View | |
16079 | CVE-2005-4875 | Candidate | TYPO3 3.8.0 and earlier allows remote attackers to obtain sensitive information via a direct request to misc/phpcheck/, which invokes the phpinfo function and prints values of unspecified environment variables. | Assigned (20080519) | None (candidate not yet proposed) | View |
Page 18596 of 20943, showing 5 records out of 104715 total, starting on record 92976, ending on 92980