CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52195  CVE-2011-4283  Candidate  Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 places an IMS enterprise enrolment file in the course-files area, which allows remote attackers to obtain sensitive information via a request for imsenterprise-enrol.xml.  Assigned (20111104)  None (candidate not yet proposed)    View
52451  CVE-2011-4539  Candidate  dhcpd in ISC DHCP 4.x before 4.2.3-P1 and 4.1-ESV before 4.1-ESV-R4 does not properly handle regular expressions in dhcpd.conf, which allows remote attackers to cause a denial of service (daemon crash) via a crafted request packet.  Assigned (20111122)  None (candidate not yet proposed)    View
52707  CVE-2011-4795  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20111213)  None (candidate not yet proposed)    View
52963  CVE-2011-5051  Candidate  Multiple unrestricted file upload vulnerabilities in the WP Symposium plugin before 11.12.24 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension using (1) uploadify/upload_admin_avatar.php or (2) uploadify/upload_profile_avatar.php, then accessing it via a direct request to the file in an unspecified directory inside the webroot.  Assigned (20120104)  None (candidate not yet proposed)    View
53219  CVE-2011-5307  Candidate  Cross-site scripting (XSS) vulnerability in index.php in the PhotoSmash plugin 1.0.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the action parameter.  Assigned (20150101)  None (candidate not yet proposed)    View

Page 18688 of 20943, showing 5 records out of 104715 total, starting on record 93436, ending on 93440

Actions