CVE List

Id CVE No. Status Description Phase Votes Comments Actions
43021  CVE-2010-0437  Candidate  The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle certain circumstances involving an IPv6 TUN network interface and a large number of neighbors, which allows attackers to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via unknown vectors.  Assigned (20100127)  None (candidate not yet proposed)    View
43277  CVE-2010-0693  Candidate  SQL injection vulnerability in products.php in CommodityRentals Trade Manager Script allows remote attackers to execute arbitrary SQL commands via the cid parameter.  Assigned (20100223)  None (candidate not yet proposed)    View
43533  CVE-2010-0949  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Natychmiast CMS allow remote attackers to inject arbitrary web script or HTML via the id_str parameter to (1) index.php and (2) a_index.php.  Assigned (20100309)  None (candidate not yet proposed)    View
43789  CVE-2010-1205  Candidate  Buffer overflow in pngpread.c in libpng before 1.2.44 and 1.4.x before 1.4.3, as used in progressive applications, might allow remote attackers to execute arbitrary code via a PNG image that triggers an additional data row.  Assigned (20100330)  None (candidate not yet proposed)    View
44045  CVE-2010-1461  Candidate  Directory traversal vulnerability in the Photo Battle (com_photobattle) component 1.0.1 for Joomla! allows remote attackers to read arbitrary files via the view parameter to index.php.  Assigned (20100416)  None (candidate not yet proposed)    View

Page 1099 of 20943, showing 5 records out of 104715 total, starting on record 5491, ending on 5495

Actions