NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
11584  CVE-2010-0004  ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private root names by reading this view.    Medium  2017-01-18  2010-02-02  View
52138  CVE-2009-5024  ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks, via the limit parameter, as demonstrated by a "query revision history" request.    Medium  2017-01-07  2012-11-19  View
1250  CVE-2008-1291  ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read files and list folders under the hidden CVSROOT folder.    4.3  Medium  2017-01-03  2009-08-20  View
1251  CVE-2008-1292  ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1) forbidden pathnames in the revision view, (2) log history that can only be reached by traversing a forbidden object, or (3) forbidden diff view path parameters.    4.3  Medium  2017-01-03  2009-08-20  View
1249  CVE-2008-1290  ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attackers to obtain sensitive information.    4.3  Medium  2017-01-03  2009-08-20  View

Page 623 of 17672, showing 5 records out of 88360 total, starting on record 3111, ending on 3115

Actions