CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42764  CVE-2010-0180  Candidate  Install/Filesystem.pm in Bugzilla 3.5.1 through 3.6 and 3.7, when use_suexec is enabled, uses world-readable permissions for the localconfig files, which allows local users to read sensitive configuration fields, as demonstrated by the database password field and the site_wide_secret field.  Assigned (20100106)  None (candidate not yet proposed)    View
43020  CVE-2010-0436  Candidate  Race condition in backend/ctrl.c in KDM in KDE Software Compilation (SC) 2.2.0 through 4.4.2 allows local users to change the permissions of arbitrary files, and consequently gain privileges, by blocking the removal of a certain directory that contains a control socket, related to improper interaction with ksm.  Assigned (20100127)  None (candidate not yet proposed)    View
43276  CVE-2010-0692  Candidate  SQL injection vulnerability in the IP-Tech JQuarks (com_jquarks) Component 0.2.3, and possibly earlier, for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. NOTE: some of these details are obtained from third party information.  Assigned (20100223)  None (candidate not yet proposed)    View
43532  CVE-2010-0948  Candidate  SQL injection vulnerability in profil.php in Bigforum 4.5, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20100309)  None (candidate not yet proposed)    View
43788  CVE-2010-1204  Candidate  Search.pm in Bugzilla 2.17.1 through 3.2.6, 3.3.1 through 3.4.6, 3.5.1 through 3.6, and 3.7 allows remote attackers to obtain potentially sensitive time-tracking information via a crafted search URL, related to a "boolean chart search."  Assigned (20100330)  None (candidate not yet proposed)    View

Page 1031 of 20943, showing 5 records out of 104715 total, starting on record 5151, ending on 5155

Actions