CVE List

Id CVE No. Status Description Phase Votes Comments Actions
52467  CVE-2011-4555  Candidate  One Click Orgs before 1.2.3 does not require unique e-mail addresses for user accounts, which allows remote authenticated users to cause a denial of service (login disruption) or spoof votes or comments by selecting a conflicting e-mail address.  Assigned (20111127)  None (candidate not yet proposed)    View
52723  CVE-2011-4811  Candidate  SQL injection vulnerability in pokaz_podkat.php in BestShopPro allows remote attackers to execute arbitrary SQL commands via the str parameter.  Assigned (20111213)  None (candidate not yet proposed)    View
52979  CVE-2011-5067  Candidate  move_uploaded_file.php in Support Incident Tracker (aka SiT!) 3.65 allows remote authenticated users to obtain sensitive information via the file name, which reveals the installation path in an error message.  Assigned (20120128)  None (candidate not yet proposed)    View
53235  CVE-2011-5323  Candidate  GE Healthcare Centricity PACS-IW 3.7.3.7, 3.7.3.8, and possibly other versions has a password of A11enda1e for the sa SQL server user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.  Assigned (20150705)  None (candidate not yet proposed)    View
53491  CVE-2012-0248  Candidate  ImageMagick 6.7.5-7 and earlier allows remote attackers to cause a denial of service (infinite loop and hang) via a crafted image whose IFD contains IOP tags that all reference the beginning of the IDF.  Assigned (20111221)  None (candidate not yet proposed)    View

Page 19972 of 20943, showing 5 records out of 104715 total, starting on record 99856, ending on 99860

Actions