CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42459  CVE-2009-5024  Candidate  ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks, via the limit parameter, as demonstrated by a "query revision history" request.  Assigned (20101209)  None (candidate not yet proposed)    View
31408  CVE-2008-1291  Candidate  ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read files and list folders under the hidden CVSROOT folder.  Assigned (20080312)  None (candidate not yet proposed)    View
31409  CVE-2008-1292  Candidate  ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1) forbidden pathnames in the revision view, (2) log history that can only be reached by traversing a forbidden object, or (3) forbidden diff view path parameters.  Assigned (20080312)  None (candidate not yet proposed)    View
31407  CVE-2008-1290  Candidate  ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attackers to obtain sensitive information.  Assigned (20080312)  None (candidate not yet proposed)    View
21546  CVE-2006-5442  Candidate  ViewVC 1.0.2 and earlier does not specify a charset in its HTTP headers or HTML documents, which allows remote attackers to conduct cross-site scripting (XSS) attacks that inject arbitrary UTF-7 encoded JavaScript code via a view.  Assigned (20061020)  None (candidate not yet proposed)    View

Page 546 of 20943, showing 5 records out of 104715 total, starting on record 2726, ending on 2730

Actions