CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46095  CVE-2010-3511  Candidate  Unspecified vulnerability in Oracle OpenSolaris allows local users to affect integrity and availability via unknown vectors related to Tooltalk.  Assigned (20100920)  None (candidate not yet proposed)    View
46351  CVE-2010-3767  Candidate  Integer overflow in the NewIdArray function in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via a JavaScript array with many elements.  Assigned (20101005)  None (candidate not yet proposed)    View
46607  CVE-2010-4023  Candidate  Cross-site scripting (XSS) vulnerability in HP Insight Control Power Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20101021)  None (candidate not yet proposed)    View
46863  CVE-2010-4279  Candidate  The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter.  Assigned (20101117)  None (candidate not yet proposed)    View
47119  CVE-2010-4535  Candidate  The password reset functionality in django.contrib.auth in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote attackers to cause a denial of service (resource consumption) via a URL that specifies a large base36 integer.  Assigned (20101209)  None (candidate not yet proposed)    View

Page 1255 of 20943, showing 5 records out of 104715 total, starting on record 6271, ending on 6275

Actions