CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51703  CVE-2011-3791  Candidate  Piwik 1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/Widgetize/Widgetize.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View
51959  CVE-2011-4047  Candidate  The Dell KACE K2000 System Deployment Appliance allows remote attackers to execute arbitrary commands by leveraging database write access.  Assigned (20111013)  None (candidate not yet proposed)    View
52215  CVE-2011-4303  Candidate  lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.  Assigned (20111104)  None (candidate not yet proposed)    View
52471  CVE-2011-4559  Candidate  SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php.  Assigned (20111128)  None (candidate not yet proposed)    View
52727  CVE-2011-4815  Candidate  Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.  Assigned (20111214)  None (candidate not yet proposed)    View

Page 19686 of 20943, showing 5 records out of 104715 total, starting on record 98426, ending on 98430

Actions