CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
52467 | CVE-2011-4555 | Candidate | One Click Orgs before 1.2.3 does not require unique e-mail addresses for user accounts, which allows remote authenticated users to cause a denial of service (login disruption) or spoof votes or comments by selecting a conflicting e-mail address. | Assigned (20111127) | None (candidate not yet proposed) | View | |
52723 | CVE-2011-4811 | Candidate | SQL injection vulnerability in pokaz_podkat.php in BestShopPro allows remote attackers to execute arbitrary SQL commands via the str parameter. | Assigned (20111213) | None (candidate not yet proposed) | View | |
52979 | CVE-2011-5067 | Candidate | move_uploaded_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, which reveals the installation path in an error message. | Assigned (20120128) | None (candidate not yet proposed) | View | |
53235 | CVE-2011-5323 | Candidate | GE Healthcare Centricity PACS-IW 3.7.3.7, 3.7.3.8, and possibly other versions has a password of A11enda1e for the sa SQL server user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value. | Assigned (20150705) | None (candidate not yet proposed) | View | |
53491 | CVE-2012-0248 | Candidate | ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF. | Assigned (20111221) | None (candidate not yet proposed) | View |
Page 19972 of 20943, showing 5 records out of 104715 total, starting on record 99856, ending on 99860