CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
46095 | CVE-2010-3511 | Candidate | Unspecified vulnerability in Oracle OpenSolaris allows local users to affect integrity and availability via unknown vectors related to Tooltalk. | Assigned (20100920) | None (candidate not yet proposed) | View | |
46351 | CVE-2010-3767 | Candidate | Integer overflow in the NewIdArray function in Mozilla Firefox before 3.5.16 and 3.6.x before 3.6.13, and SeaMonkey before 2.0.11, allows remote attackers to execute arbitrary code via a JavaScript array with many elements. | Assigned (20101005) | None (candidate not yet proposed) | View | |
46607 | CVE-2010-4023 | Candidate | Cross-site scripting (XSS) vulnerability in HP Insight Control Power Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20101021) | None (candidate not yet proposed) | View | |
46863 | CVE-2010-4279 | Candidate | The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter. | Assigned (20101117) | None (candidate not yet proposed) | View | |
47119 | CVE-2010-4535 | Candidate | The password reset functionality in django.contrib.auth in Django before 1.1.3, 1.2.x before 1.2.4, and 1.3.x before 1.3 beta 1 does not validate the length of a string representing a base36 timestamp, which allows remote attackers to cause a denial of service (resource consumption) via a URL that specifies a large base36 integer. | Assigned (20101209) | None (candidate not yet proposed) | View |
Page 1255 of 20943, showing 5 records out of 104715 total, starting on record 6271, ending on 6275