Skip to main content

CWE archive

CWE-16 CVEs

Programmatic archive

318 CVEs tagged with CWE-1647 Critical, 77 High, 163 Medium, 31 Low, 0 Unrated.

CVE-2012-5526

Published Nov 21, 2012

CGI.pm module before 3.63 for Perl does not properly escape newlines in (1) Set-Cookie or (2) P3P headers, which might allow remote attackers to inject arbitrary headers into resp…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4537

Published Nov 21, 2012

Xen 3.4 through 4.2, and possibly earlier versions, does not properly synchronize the p2m and m2p tables when the set_p2m_entry function fails, which allows local HVM guest OS adm…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-3413

Published Aug 7, 2012

The HTMLQuoteColorer::process function in messageviewer/htmlquotecolorer.cpp in KDE PIM 4.6 through 4.8 does not disable JavaScript, Java, and Plugins, which allows remote attacke…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1909

Published Aug 6, 2012

The Bitcoin protocol, as used in bitcoind before 0.4.4, wxBitcoin, Bitcoin-Qt, and other programs, does not properly handle multiple transactions with the same identifier, which a…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-3392

Published Jul 23, 2012

mod/forum/unsubscribeall.php in Moodle 2.1.x before 2.1.7 and 2.2.x before 2.2.4 does not consider whether a forum is optional, which allows remote authenticated users to bypass f…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4585

Published Jul 20, 2012

login/change_password.php in Moodle 1.9.x before 1.9.15 does not use https for the change-password form even if the httpslogin option is enabled, which allows remote attackers to…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0797

Published Jul 17, 2012

The webservices functionality in Moodle 2.0.x before 2.0.7, 2.1.x before 2.1.4, and 2.2.x before 2.2.1 allows remote authenticated users to bypass the deleted status and continue…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-0147

Published Apr 10, 2012

Microsoft Forefront Unified Access Gateway (UAG) 2010 SP1 and SP1 Update 1 does not properly configure the default web site, which allows remote attackers to obtain sensitive info…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-4504

Published Nov 22, 2011

The UPnP IGD implementation in the Pseudo ICS UPnP software on the ZyXEL P-330W allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping actio…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4503

Published Nov 22, 2011

The UPnP IGD implementation in Broadcom Linux on the Sitecom WL-111 allows remote attackers to establish arbitrary port mappings by sending a UPnP AddPortMapping action in a SOAP…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-4501

Published Nov 22, 2011

The UPnP IGD implementation in Edimax EdiLinux on the Edimax BR-6104K with firmware before 3.25, Edimax 6114Wg, Canyon-Tech CN-WF512 with firmware 1.83, Canyon-Tech CN-WF514 with…

CVSS 10.0 · Critical

CVE-2011-4404

Published Nov 19, 2011

The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 before Update 4 and 4.1 before Update 2 allows remote attacker…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-1370

Published Oct 29, 2011

The default configuration of the Sametime configuration servlet (SCS) in the server in IBM Lotus Sametime 7.0 through 8.5.2 does not enable an authentication requirement, which al…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2000-1247

Published Oct 5, 2011

The default configuration of the jserv-status handler in jserv.conf in Apache JServ 1.1.2 includes an "allow from 127.0.0.1" line, which allows local users to discover JDBC passwo…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2011-3008

Published Aug 5, 2011

The default configuration of Avaya Secure Access Link (SAL) Gateway 1.5, 1.8, and 2.0 contains certain domain names in the Secondary Core Server URL and Secondary Remote Server UR…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2666

Published Jul 6, 2011

The default configuration of the SIP channel driver in Asterisk Open Source 1.4.x through 1.4.41.2 and 1.6.2.x through 1.6.2.18.2 does not enable the alwaysauthreject option, whic…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-2395

Published Jun 9, 2011

The Neighbor Discovery (ND) protocol implementation in Cisco IOS on unspecified switches allows remote attackers to bypass the Router Advertisement Guarding functionality via a fr…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 101-125 of 318 CVEsPage 5 of 13