CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52209  CVE-2011-4297  Candidate  comment/lib.php in Moodle 2.0.x before 2.0.4 and 2.1.x before 2.1.1 does not properly restrict comment capabilities, which allows remote attackers to post a comment by leveraging the guest role and operating on a front-page activity.  Assigned (20111104)  None (candidate not yet proposed)    View
52465  CVE-2011-4553  Candidate  Multiple open redirect vulnerabilities in One Click Orgs before 1.2.3 allow (1) remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the return_to parameter, and allow (2) remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via crafted characters in the domain name of a subdomain.  Assigned (20111127)  None (candidate not yet proposed)    View
52721  CVE-2011-4809  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the HM Community (com_hmcommunity) component before 1.01 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) language[], (2) university[], (3) persent[], (4) company_name[], (5) designation[], (6) music[], (7) books[], (8) movies[], (9) games[], (10) syp[], (11) ft[], and (12) fa[] parameters in a save task for a profile to index.php. NOTE: some of these details are obtained from third party information.  Assigned (20111213)  None (candidate not yet proposed)    View
52977  CVE-2011-5065  Candidate  Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.41 allows remote attackers to inject arbitrary web script or HTML via vectors related to web messaging.  Assigned (20120114)  None (candidate not yet proposed)    View
53233  CVE-2011-5321  Candidate  The tty_open function in drivers/tty/tty_io.c in the Linux kernel before 3.1.1 mishandles a driver-lookup failure, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via crafted access to a device file under the /dev/pts directory.  Assigned (20150313)  None (candidate not yet proposed)    View

Page 19820 of 20943, showing 5 records out of 104715 total, starting on record 99096, ending on 99100

Actions