CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51439  CVE-2011-3527  Candidate  Unspecified vulnerability in the PeopleSoft Enterprise HRMS component in Oracle PeopleSoft Products 9.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Candidate Gateway.  Assigned (20110916)  None (candidate not yet proposed)    View
51695  CVE-2011-3783  Candidate  phpMyFAQ 2.6.13 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by lang/language_uk.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View
51951  CVE-2011-4039  Candidate  Invensys Wonderware HMI Reports 3.42.835.0304 and earlier, as used in Ocean Data Systems Dream Report before 4.0 and other products, allows user-assisted remote attackers to execute arbitrary code via a malformed file that triggers a "write access violation."  Assigned (20111013)  None (candidate not yet proposed)    View
52207  CVE-2011-4295  Candidate  The moodle_enrol_external:role_assign function in enrol/externallib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not have an authorization check, which allows remote authenticated users to gain privileges by making a role assignment.  Assigned (20111104)  None (candidate not yet proposed)    View
52463  CVE-2011-4551  Candidate  Cross-site scripting (XSS) vulnerability in tiki-cookie-jar.php in TikiWiki CMS/Groupware before 8.2 and LTS before 6.5 allows remote attackers to inject arbitrary web script or HTML via arbitrary parameters.  Assigned (20111127)  None (candidate not yet proposed)    View

Page 19663 of 20943, showing 5 records out of 104715 total, starting on record 98311, ending on 98315

Actions