CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
51959 | CVE-2011-4047 | Candidate | The Dell KACE K2000 System Deployment Appliance allows remote attackers to execute arbitrary commands by leveraging database write access. | Assigned (20111013) | None (candidate not yet proposed) | View | |
52215 | CVE-2011-4303 | Candidate | lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature. | Assigned (20111104) | None (candidate not yet proposed) | View | |
52471 | CVE-2011-4559 | Candidate | SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php. | Assigned (20111128) | None (candidate not yet proposed) | View | |
52727 | CVE-2011-4815 | Candidate | Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table. | Assigned (20111214) | None (candidate not yet proposed) | View | |
52983 | CVE-2011-5071 | Candidate | Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL commands via the (1) exc[] parameter to report_marketing.php, (2) selected[] parameter to tasks.php, (3) sites[] parameter to billable_incidents.php, or (4) search_string parameter to search.php. NOTE: some of these details are obtained from third party information. | Assigned (20120128) | None (candidate not yet proposed) | View |
Page 20280 of 20943, showing 5 records out of 104715 total, starting on record 101396, ending on 101400