CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51959  CVE-2011-4047  Candidate  The Dell KACE K2000 System Deployment Appliance allows remote attackers to execute arbitrary commands by leveraging database write access.  Assigned (20111013)  None (candidate not yet proposed)    View
52215  CVE-2011-4303  Candidate  lib/db/upgrade.php in Moodle 2.0.x before 2.0.5 and 2.1.x before 2.1.2 does not set the correct registration_hubs.secret value during installation, which allows remote attackers to bypass intended access restrictions by leveraging the hubs feature.  Assigned (20111104)  None (candidate not yet proposed)    View
52471  CVE-2011-4559  Candidate  SQL injection vulnerability in the Calendar module in vTiger CRM 5.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php.  Assigned (20111128)  None (candidate not yet proposed)    View
52727  CVE-2011-4815  Candidate  Ruby (aka CRuby) before 1.8.7-p357 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.  Assigned (20111214)  None (candidate not yet proposed)    View
52983  CVE-2011-5071  Candidate  Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to execute arbitrary SQL commands via the (1) exc[] parameter to report_marketing.php, (2) selected[] parameter to tasks.php, (3) sites[] parameter to billable_incidents.php, or (4) search_string parameter to search.php. NOTE: some of these details are obtained from third party information.  Assigned (20120128)  None (candidate not yet proposed)    View

Page 20280 of 20943, showing 5 records out of 104715 total, starting on record 101396, ending on 101400

Actions