CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
51439 | CVE-2011-3527 | Candidate | Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Candidate Gateway. | Assigned (20110916) | None (candidate not yet proposed) | View | |
51695 | CVE-2011-3783 | Candidate | phpMyFAQ 2.6.13 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lang/language_uk.php and certain other files. | Assigned (20110923) | None (candidate not yet proposed) | View | |
51951 | CVE-2011-4039 | Candidate | Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access violation." | Assigned (20111013) | None (candidate not yet proposed) | View | |
52207 | CVE-2011-4295 | Candidate | The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment. | Assigned (20111104) | None (candidate not yet proposed) | View | |
52463 | CVE-2011-4551 | Candidate | Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters. | Assigned (20111127) | None (candidate not yet proposed) | View |
Page 19663 of 20943, showing 5 records out of 104715 total, starting on record 98311, ending on 98315