CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52203  CVE-2011-4291  Candidate  Moodle 2.0.x before 2.0.3 allows remote authenticated users to cause a denial of service (invalid database records) via a series of crafted ratings operations.  Assigned (20111104)  None (candidate not yet proposed)    View
52459  CVE-2011-4547  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in includes/templates/template_default/common/tpl_header_test_info.php in Zen Cart 1.3.9h, when debugging is enabled, might allow remote attackers to inject arbitrary web script or HTML via the (1) main_page parameter or (2) PATH_INFO, a different vulnerability than CVE-2011-4567.  Assigned (20111123)  None (candidate not yet proposed)    View
52715  CVE-2011-4803  Candidate  SQL injection vulnerability in wptouch/ajax.php in the WPTouch plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20111213)  None (candidate not yet proposed)    View
52971  CVE-2011-5059  Candidate  Stack-based buffer overflow in Final Draft 8 before 8.02 allows remote attackers to execute arbitrary code via a crafted SmartType element, a different vulnerability than CVE-2011-5002. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20120110)  None (candidate not yet proposed)    View
53227  CVE-2011-5315  Candidate  Cross-site request forgery (CSRF) vulnerability in admin/index.php in whCMS 0.115 alpha allows remote attackers to hijack the authentication of administrators for requests that modify credentials via a user save action.  Assigned (20150101)  None (candidate not yet proposed)    View

Page 19331 of 20943, showing 5 records out of 104715 total, starting on record 96651, ending on 96655

Actions