CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
52198 | CVE-2011-4286 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in the media-filter implementation in filter/mediaplugin/filter.php in Moodle 1.9.x before 1.9.11 and 2.0.x before 2.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) Flash Video (aka FLV) files and (2) YouTube videos. | Assigned (20111104) | None (candidate not yet proposed) | View | |
52454 | CVE-2011-4542 | Candidate | Hastymail2 2.1.1 before RC2 allows remote attackers to execute arbitrary commands via the (1) rs or (2) rsargs[] parameter in a mailbox Drafts action to the default URI. | Assigned (20111123) | None (candidate not yet proposed) | View | |
52710 | CVE-2011-4798 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20111213) | None (candidate not yet proposed) | View | |
52966 | CVE-2011-5054 | Candidate | kcheckpass passes a user-supplied argument to the pam_start function, often within a setuid environment, which allows local users to invoke any configured PAM stack, and possibly trigger unintended side effects, via an arbitrary valid PAM service name, a different vulnerability than CVE-2011-4122. NOTE: the vendor indicates that the possibility of resultant privilege escalation may be "a bit far-fetched." | Assigned (20120106) | None (candidate not yet proposed) | View | |
53222 | CVE-2011-5310 | Candidate | Directory traversal vulnerability in pages.php in Wikipad 1.6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter. | Assigned (20150101) | None (candidate not yet proposed) | View |
Page 18929 of 20943, showing 5 records out of 104715 total, starting on record 94641, ending on 94645