CVE List

Id CVE No. Status Description Phase Votes Comments Actions
44307  CVE-2010-1723  Candidate  Directory traversal vulnerability in the iNetLanka Contact Us Draw Root Map (com_drawroot) component 1.1 for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the controller parameter to index.php.  Assigned (20100504)  None (candidate not yet proposed)    View
44563  CVE-2010-1979  Candidate  Directory traversal vulnerability in the Affiliate Datafeeds (com_datafeeds) component build 880 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php.  Assigned (20100519)  None (candidate not yet proposed)    View
44819  CVE-2010-2235  Candidate  template_api.py in Cobbler before 2.0.7, as used in Red Hat Network Satellite Server and other products, does not disable the ability of the Cheetah template engine to execute Python statements contained in templates, which allows remote authenticated administrators to execute arbitrary code via a crafted kickstart template file, a different vulnerability than CVE-2008-6954.  Assigned (20100609)  None (candidate not yet proposed)    View
45075  CVE-2010-2491  Candidate  Cross-site scripting (XSS) vulnerability in cgi/client.py in Roundup before 1.4.14 allows remote attackers to inject arbitrary web script or HTML via the template argument to the /issue program.  Assigned (20100628)  None (candidate not yet proposed)    View
45331  CVE-2010-2747  Candidate  Microsoft Word 2002 SP3 and Office 2004 for Mac do not properly handle an uninitialized pointer during parsing of a Word document, which allows remote attackers to execute arbitrary code via a crafted document that triggers memory corruption, aka "Word Uninitialized Pointer Vulnerability."  Assigned (20100714)  None (candidate not yet proposed)    View

Page 1596 of 20943, showing 5 records out of 104715 total, starting on record 7976, ending on 7980

Actions