NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 28966 | CVE-2014-0009 | course/loginas.php in Moodle through 2.2.11, 2.3.x before 2.3.11, 2.4.x before 2.4.8, 2.5.x before 2.5.4, and 2.6.x before 2.6.1 does not enforce the moodle/site:accessallgroups capability requirement for outside-group users in a SEPARATEGROUPS configuration, which allows remote authenticated users to perform "login as" actions via a direct request. | 2 | 5.5 | Medium | 2017-01-19 | 2014-02-21 | View | |
| 63551 | CVE-2006-4943 | course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbitrary local URIs, which allows remote attackers to obtain sensitive information via the jump parameter. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 6743 | CVE-2008-7012 | courier/1000@/api_error_email.html (aka "error reporting page") in Accellion File Transfer Appliance FTA_7_0_178, and possibly other versions before FTA_7_0_189, allows remote attackers to send spam e-mail via modified description and client_email parameters. | 2 | 7.8 | High | 2017-01-03 | 2010-03-05 | View | |
| 80275 | CVE-2002-1311 | Courier sqwebmail before 0.40.0 does not quickly drop privileges after startup in certain cases, which could allow local users to read arbitrary files. | 2 | 4.6 | Medium | 2017-01-05 | 2016-10-17 | View | |
| 56507 | CVE-2007-4382 | CounterPath X-Lite 3.0 34025, and possibly eyeBeam, allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Content-Type header. | 2 | 5 | Medium | 2017-01-07 | 2008-09-05 | View |
Page 14988 of 17672, showing 5 records out of 88360 total, starting on record 74936, ending on 74940