CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52503  CVE-2011-4591  Candidate  Cross-site scripting (XSS) vulnerability in the print_object function in lib/datalib.php in Moodle 2.0.x before 2.0.6 and 2.1.x before 2.1.3, when a developer debugging script is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors involving object states.  Assigned (20111129)  None (candidate not yet proposed)    View
52759  CVE-2011-4847  Candidate  SQL injection vulnerability in the Control Panel in Parallels Plesk Panel 10.4.4_build20111103.18 allows remote attackers to execute arbitrary SQL commands via a certificateslist cookie to notification@/.  Assigned (20111215)  None (candidate not yet proposed)    View
53015  CVE-2011-5103  Candidate  SQL injection vulnerability in Alurian Prismotube PHP Video Script allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.  Assigned (20120823)  None (candidate not yet proposed)    View
53271  CVE-2012-0028  Candidate  The robust futex implementation in the Linux kernel before 2.6.28 does not properly handle processes that make exec system calls, which allows local users to cause a denial of service or possibly gain privileges by writing to a memory location in a child process.  Assigned (20111207)  None (candidate not yet proposed)    View
53527  CVE-2012-0284  Candidate  Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.ocx on the Cisco WVC200 Wireless-G PTZ Internet video camera allows remote attackers to execute arbitrary code via a long URL in the first argument (aka the sURL argument).  Assigned (20111230)  None (candidate not yet proposed)    View

Page 1899 of 20943, showing 5 records out of 104715 total, starting on record 9491, ending on 9495

Actions