CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
42764 | CVE-2010-0180 | Candidate | Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database password field and the site_wide_secret field. | Assigned (20100106) | None (candidate not yet proposed) | View | |
43020 | CVE-2010-0436 | Candidate | Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm. | Assigned (20100127) | None (candidate not yet proposed) | View | |
43276 | CVE-2010-0692 | Candidate | SQL injection vulnerability in the IP-Tech JQuarks (com_jquarks) Component 0.2.3, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. NOTE: some of these details are obtained from third party information. | Assigned (20100223) | None (candidate not yet proposed) | View | |
43532 | CVE-2010-0948 | Candidate | SQL injection vulnerability in profil.php in Bigforum 4.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20100309) | None (candidate not yet proposed) | View | |
43788 | CVE-2010-1204 | Candidate | Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a crafted search URL, related to a "boolean chart search." | Assigned (20100330) | None (candidate not yet proposed) | View |
Page 1022 of 20943, showing 5 records out of 104715 total, starting on record 5106, ending on 5110