CVE List

Id CVE No. Status Description Phase Votes Comments Actions
7225  CVE-2003-0398  Candidate  Vignette StoryServer 4 and 5, and Vignette V/5 and V/6, with the SSI EXEC feature enabled, allows remote attackers to execute arbitrary code via a text variable to a Vignette Application that is later displayed.  Assigned (20030610)  None (candidate not yet proposed)    View
4777  CVE-2002-0385  Candidate  Vignette Story Server 4.1 and 6.0 allows remote attackers to obtain sensitive information via a request that contains a large number of """ (double quote) and and ">" characters, which causes the TCL interpreter to crash and include stack data in the output.  Assigned (20020522)  None (candidate not yet proposed)    View
56770  CVE-2012-3527  Candidate  view_help.php in the backend help system in TYPO3 4.5.x before 4.5.19, 4.6.x before 4.6.12 and 4.7.x before 4.7.4 allows remote authenticated backend users to unserialize arbitrary objects and possibly execute arbitrary PHP code via an unspecified parameter, related to a "missing signature (HMAC)."  Assigned (20120614)  None (candidate not yet proposed)    View
18567  CVE-2006-2463  Candidate  view_album.php in SelectaPix 1.31 and earlier allows remote attackers to obtain the installation path via a certain request, which displays the path in an error message, possibly due to an invalid or missing parameter.  Assigned (20060519)  None (candidate not yet proposed)    View
42588  CVE-2010-0004  Candidate  ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private root names by reading this view.  Assigned (20091214)  None (candidate not yet proposed)    View

Page 545 of 20943, showing 5 records out of 104715 total, starting on record 2721, ending on 2725

Actions