CVE List

Id CVE No. Status Description Phase Votes Comments Actions
50668  CVE-2011-2756  Candidate  FileDownload.jsp in ManageEngine ServiceDesk Plus 8.0 before Build 8012 does not require authentication, which allows remote attackers to read files from a specific directory via unspecified vectors.  Assigned (20110717)  None (candidate not yet proposed)    View
50924  CVE-2011-3012  Candidate  The ioQuake3 engine, as used in World of Padman 1.2 and earlier, Tremulous 1.1.0, and ioUrbanTerror 2007-12-20, does not check for dangerous file extensions before writing to the quake3 directory, which allows remote attackers to execute arbitrary code via a crafted third-party addon that creates a Trojan horse DLL file, a different vulnerability than CVE-2011-2764.  Assigned (20110809)  None (candidate not yet proposed)    View
51180  CVE-2011-3268  Candidate  Buffer overflow in the crypt function in PHP before 5.3.7 allows context-dependent attackers to have an unspecified impact via a long salt argument, a different vulnerability than CVE-2011-2483.  Assigned (20110825)  None (candidate not yet proposed)    View
51436  CVE-2011-3524  Candidate  Unspecified vulnerability in the EnterpriseOne Tools component in Oracle JD Edwards 8.98 SP 24 allows remote authenticated users to affect confidentiality, related to Enterprise Infrastructure SEC (JDENET), a different vulnerability than CVE-2011-2325, CVE-2011-2326, and CVE-2011-3509.  Assigned (20110916)  None (candidate not yet proposed)    View
51692  CVE-2011-3780  Candidate  PHP iCalendar 2.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by rss/rss_common.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View

Page 19410 of 20943, showing 5 records out of 104715 total, starting on record 97046, ending on 97050

Actions