CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
51703 | CVE-2011-3791 | Candidate | Piwik 1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by plugins/Widgetize/Widgetize.php and certain other files. | Assigned (20110923) | None (candidate not yet proposed) | View | |
51959 | CVE-2011-4047 | Candidate | The Dell KACE K2000 System Deployment Appliance allows remote attackers to execute arbitrary commands by leveraging database write access. | Assigned (20111013) | None (candidate not yet proposed) | View | |
52215 | CVE-2011-4303 | Candidate | lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature. | Assigned (20111104) | None (candidate not yet proposed) | View | |
52471 | CVE-2011-4559 | Candidate | SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php. | Assigned (20111128) | None (candidate not yet proposed) | View | |
52727 | CVE-2011-4815 | Candidate | Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. | Assigned (20111214) | None (candidate not yet proposed) | View |
Page 19686 of 20943, showing 5 records out of 104715 total, starting on record 98426, ending on 98430