CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42258  CVE-2009-4823  Candidate  Cross-site scripting (XSS) vulnerability in frontend/x3/files/fileop.html in cPanel 11.0 through 11.24.7 allows remote attackers to inject arbitrary web script or HTML via the fileop parameter.  Assigned (20100427)  None (candidate not yet proposed)    View
42514  CVE-2009-5079  Candidate  The (1) gendef.sh, (2) doc/fixinfo.sh, and (3) contrib/gdiffmk/tests/runtests.in scripts in GNU troff (aka groff) 1.21 and earlier allow local users to overwrite arbitrary files via a symlink attack on a gro#####.tmp or /tmp/##### temporary file.  Assigned (20110630)  None (candidate not yet proposed)    View
42770  CVE-2010-0186  Candidate  Cross-domain vulnerability in Adobe Flash Player before 10.0.45.2, Adobe AIR before 1.5.3.9130, and Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows remote attackers to bypass intended sandbox restrictions and make cross-domain requests via unspecified vectors.  Assigned (20100106)  None (candidate not yet proposed)    View
43026  CVE-2010-0442  Candidate  The bitsubstr function in backend/utils/adt/varbit.c in PostgreSQL 8.0.23, 8.1.11, and 8.3.8 allows remote authenticated users to cause a denial of service (daemon crash) or have unspecified other impact via vectors involving a negative integer in the third argument, as demonstrated by a SELECT statement that contains a call to the substring function for a bit string, related to an "overflow."  Assigned (20100127)  None (candidate not yet proposed)    View
43282  CVE-2010-0698  Candidate  SQL injection vulnerability in backoffice/login.asp in Dynamicsoft WSC CMS 2.2 allows remote attackers to execute arbitrary SQL commands via the Password parameter. NOTE: some of these details are obtained from third party information.  Assigned (20100223)  None (candidate not yet proposed)    View

Page 1483 of 20943, showing 5 records out of 104715 total, starting on record 7411, ending on 7415

Actions