CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
51991 | CVE-2011-4079 | Candidate | Off-by-one error in the UTF8StringNormalize function in OpenLDAP 2.4.26 and earlier allows remote attackers to cause a denial of service (slapd crash) via a zero-length string that triggers a heap-based buffer overflow, as demonstrated using an empty postalAddressAttribute value in an LDIF entry. | Assigned (20111018) | None (candidate not yet proposed) | View | |
52247 | CVE-2011-4335 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Contao before 2.10.2 allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php in a (1) teachers.html or (2) teachers/ action. | Assigned (20111104) | None (candidate not yet proposed) | View | |
52503 | CVE-2011-4591 | Candidate | Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states. | Assigned (20111129) | None (candidate not yet proposed) | View | |
52759 | CVE-2011-4847 | Candidate | SQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to execute arbitrary SQL commands via a certificateslist cookie to notification@/. | Assigned (20111215) | None (candidate not yet proposed) | View | |
53015 | CVE-2011-5103 | Candidate | SQL injection vulnerability in Alurian Prismotube PHP Video Script allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | Assigned (20120823) | None (candidate not yet proposed) | View |
Page 1875 of 20943, showing 5 records out of 104715 total, starting on record 9371, ending on 9375