CVE List

Id CVE No. Status Description Phase Votes Comments Actions
49394  CVE-2011-1482  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in mainfile.php in Francisco Burzi PHP-Nuke 8.0 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts or (2) grant the administrative privilege to a user account, related to a Referer check that uses a substring comparison.  Assigned (20110321)  None (candidate not yet proposed)    View
49650  CVE-2011-1738  Candidate  HP Palm webOS 1.4.5 and 1.4.5.1 does not properly restrict Plug-in Development Kit (PDK) applications, which allows local users to gain privileges by leveraging unintended filesystem write access.  Assigned (20110419)  None (candidate not yet proposed)    View
49906  CVE-2011-1994  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20110509)  None (candidate not yet proposed)    View
50162  CVE-2011-2250  Candidate  Unspecified vulnerability in the PeopleSoft Enterprise FIN component in Oracle PeopleSoft Products 9.0 Bundle #36 and 9.1 Bundle #13 allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Receivables.  Assigned (20110602)  None (candidate not yet proposed)    View
50418  CVE-2011-2506  Candidate  setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restrict the presence of comment closing delimiters, which allows remote attackers to conduct static code injection attacks by leveraging the ability to modify the SESSION superglobal array.  Assigned (20110615)  None (candidate not yet proposed)    View

Page 19897 of 20943, showing 5 records out of 104715 total, starting on record 99481, ending on 99485

Actions