CVE List

Id CVE No. Status Description Phase Votes Comments Actions
51720  CVE-2011-3808  Candidate  The Bug Genie 2.1.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by modules/svn_integration/config.inc.php and certain other files.  Assigned (20110923)  None (candidate not yet proposed)    View
51976  CVE-2011-4064  Candidate  Cross-site scripting (XSS) vulnerability in the setup interface in phpMyAdmin 3.4.x before 3.4.6 allows remote attackers to inject arbitrary web script or HTML via a crafted value.  Assigned (20111015)  None (candidate not yet proposed)    View
52232  CVE-2011-4320  Candidate  The mod_pubsub module (mod_pubsub.erl) in ejabberd 2.1.8 and 3.0.0-alpha-3 allows remote authenticated users to cause a denial of service (infinite loop) via a stanza with a publish tag that lacks a node attribute.  Assigned (20111104)  None (candidate not yet proposed)    View
52488  CVE-2011-4576  Candidate  The SSL 3.0 implementation in OpenSSL before 0.9.8s and 1.x before 1.0.0f does not properly initialize data structures for block cipher padding, which might allow remote attackers to obtain sensitive information by decrypting the padding data sent by an SSL peer.  Assigned (20111129)  None (candidate not yet proposed)    View
52744  CVE-2011-4832  Candidate  Directory traversal vulnerability in CaupoShop Pro 2.x, CaupoShop Classic 3.01, and CaupoShop Pro 3.70 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter in a template action.  Assigned (20111214)  None (candidate not yet proposed)    View

Page 715 of 20943, showing 5 records out of 104715 total, starting on record 3571, ending on 3575

Actions