CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52207  CVE-2011-4295  Candidate  The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.  Assigned (20111104)  None (candidate not yet proposed)    View
52463  CVE-2011-4551  Candidate  Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.  Assigned (20111127)  None (candidate not yet proposed)    View
52719  CVE-2011-4807  Candidate  Directory traversal vulnerability in main.php in phpAlbum 0.4.1.16 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the var1 parameter.  Assigned (20111213)  None (candidate not yet proposed)    View
52975  CVE-2011-5063  Candidate  The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vulnerability than CVE-2011-1184.  Assigned (20120114)  None (candidate not yet proposed)    View
53231  CVE-2011-5319  Candidate  content/renderer/device_sensors/device_motion_event_pump.cc in Google Chrome before 41.0.2272.76 does not properly restrict access to high-rate accelerometer data, which makes it easier for remote attackers to capture keystrokes via a crafted web site that listens for ondevicemotion events, a different vulnerability than CVE-2015-1231.  Assigned (20150308)  None (candidate not yet proposed)    View

Page 19050 of 20943, showing 5 records out of 104715 total, starting on record 95246, ending on 95250

Actions