CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
43023 | CVE-2010-0439 | Candidate | Chip Salzenberg Deliver allows local users to cause a denial of service, obtain sensitive information, and possibly change the ownership of arbitrary files via a symlink attack on an unspecified file. | Assigned (20100127) | None (candidate not yet proposed) | View | |
43279 | CVE-2010-0695 | Candidate | Cross-site scripting (XSS) vulnerability in pages/index.php in BASIC-CMS allows remote attackers to inject arbitrary web script or HTML via the nav_id parameter. | Assigned (20100223) | None (candidate not yet proposed) | View | |
43535 | CVE-2010-0951 | Candidate | SQL injection vulnerability in go_target.php in dev4u CMS allows remote attackers to execute arbitrary SQL commands via the kontent_id parameter. | Assigned (20100309) | None (candidate not yet proposed) | View | |
43791 | CVE-2010-1207 | Candidate | Mozilla Firefox before 3.6.7 and Thunderbird before 3.1.1 do not properly implement read restrictions for CANVAS elements, which allows remote attackers to obtain sensitive cross-origin information via vectors involving reference retention and node deletion. | Assigned (20100330) | None (candidate not yet proposed) | View | |
44047 | CVE-2010-1463 | Candidate | Multiple SQL injection vulnerabilities in WebAsyst Shop-Script FREE allow attackers to execute arbitrary SQL commands via the (1) add2cart, (2) c_id, (3) categoryID, (4) list_price, (5) name, (6) new_offer, (7) price, (8) product_code, (9) productID, (10) rating, and (11) save_product parameters. | Assigned (20100416) | None (candidate not yet proposed) | View |
Page 1257 of 20943, showing 5 records out of 104715 total, starting on record 6281, ending on 6285