CVE List

Id CVE No. Status Description Phase Votes Comments Actions
43535  CVE-2010-0951  Candidate  SQL injection vulnerability in go_target.php in dev4u CMS allows remote attackers to execute arbitrary SQL commands via the kontent_id parameter.  Assigned (20100309)  None (candidate not yet proposed)    View
43791  CVE-2010-1207  Candidate  Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node deletion.  Assigned (20100330)  None (candidate not yet proposed)    View
44047  CVE-2010-1463  Candidate  Multiple SQL injection vulnerabilities in WebAsyst Shop-Script FREE allow attackers to execute arbitrary SQL commands via the (1) add2cart, (2) c_id, (3) categoryID, (4) list_price, (5) name, (6) new_offer, (7) price, (8) product_code, (9) productID, (10) rating, and (11) save_product parameters.  Assigned (20100416)  None (candidate not yet proposed)    View
44303  CVE-2010-1719  Candidate  Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.  Assigned (20100504)  None (candidate not yet proposed)    View
44559  CVE-2010-1975  Candidate  PostgreSQL 7.4 before 7.4.29, 8.0 before 8.0.25, 8.1 before 8.1.21, 8.2 before 8.2.17, 8.3 before 8.3.11, and 8.4 before 8.4.4 does not properly check privileges during certain RESET ALL operations, which allows remote authenticated users to remove arbitrary parameter settings via a (1) ALTER USER or (2) ALTER DATABASE statement.  Assigned (20100519)  None (candidate not yet proposed)    View

Page 1253 of 20943, showing 5 records out of 104715 total, starting on record 6261, ending on 6265

Actions