NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
11584 | CVE-2010-0004 | ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private root names by reading this view. | 2 | 5 | Medium | 2017-01-18 | 2010-02-02 | View | |
52138 | CVE-2009-5024 | ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks, via the limit parameter, as demonstrated by a "query revision history" request. | 2 | 5 | Medium | 2017-01-07 | 2012-11-19 | View | |
1250 | CVE-2008-1291 | ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read files and list folders under the hidden CVSROOT folder. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-20 | View | |
1251 | CVE-2008-1292 | ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1) forbidden pathnames in the revision view, (2) log history that can only be reached by traversing a forbidden object, or (3) forbidden diff view path parameters. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-20 | View | |
1249 | CVE-2008-1290 | ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attackers to obtain sensitive information. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-20 | View |
Page 623 of 17672, showing 5 records out of 88360 total, starting on record 3111, ending on 3115