CVE List

Id CVE No. Status Description Phase Votes Comments Actions
70713  CVE-2014-3417  Candidate  uPortal before 4.0.13.1 does not properly check the CONFIG permission, which allows remote authenticated users to configure portlets by leveraging the SUBSCRIBE permission for a portlet.  Assigned (20140507)  None (candidate not yet proposed)    View
17541  CVE-2006-1437  Candidate  UPOINT @1 Event Publisher stores sensitive information under the web document root with insufifcient access control, which allows remote attackers to read private comments via a direct request to eventpublisher.txt.  Assigned (20060328)  None (candidate not yet proposed)    View
60221  CVE-2013-0274  Candidate  upnp.c in libpurple in Pidgin before 2.10.7 does not properly terminate long strings in UPnP responses, which allows remote attackers to cause a denial of service (application crash) by leveraging access to the local network.  Assigned (20121206)  None (candidate not yet proposed)    View
13939  CVE-2005-2733  Candidate  upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which could allow remote attackers to execute arbitrary code.  Assigned (20050829)  None (candidate not yet proposed)    View
50657  CVE-2011-2745  Candidate  upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict the file extensions of uploaded files, which allows remote authenticated users to upload a .php file, and consequently execute arbitrary PHP code, via a write_post action to the default URI under admin/.  Assigned (20110713)  None (candidate not yet proposed)    View

Page 810 of 20943, showing 5 records out of 104715 total, starting on record 4046, ending on 4050

Actions