CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
51720 | CVE-2011-3808 | Candidate | The Bug Genie 2.1.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/svn_integration/config.inc.php and certain other files. | Assigned (20110923) | None (candidate not yet proposed) | View | |
51976 | CVE-2011-4064 | Candidate | Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value. | Assigned (20111015) | None (candidate not yet proposed) | View | |
52232 | CVE-2011-4320 | Candidate | The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a stanza with a publish tag that lacks a node attribute. | Assigned (20111104) | None (candidate not yet proposed) | View | |
52488 | CVE-2011-4576 | Candidate | The SSL 3.0 implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly initialize data structures for block cipher padding, which might allow remote attackers to obtain sensitive information by decrypting the padding data sent by an SSL peer. | Assigned (20111129) | None (candidate not yet proposed) | View | |
52744 | CVE-2011-4832 | Candidate | Directory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter in a template action. | Assigned (20111214) | None (candidate not yet proposed) | View |
Page 715 of 20943, showing 5 records out of 104715 total, starting on record 3571, ending on 3575