CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
46853 | CVE-2010-4269 | Candidate | SQL injection vulnerability in managechat.php in Collabtive 0.65 allows remote attackers to execute arbitrary SQL commands via the chatstart[USERTOID] cookie in a pull action. | Assigned (20101116) | None (candidate not yet proposed) | View | |
47109 | CVE-2010-4525 | Candidate | Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via unspecified vectors. | Assigned (20101209) | None (candidate not yet proposed) | View | |
47365 | CVE-2010-4781 | Candidate | index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive information via a crafted title parameter, which reveals the installation path in an error message. | Assigned (20110407) | None (candidate not yet proposed) | View | |
47621 | CVE-2010-5037 | Candidate | SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id parameter. | Assigned (20111102) | None (candidate not yet proposed) | View | |
47877 | CVE-2010-5293 | Candidate | wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match. | Assigned (20140120) | None (candidate not yet proposed) | View |
Page 1610 of 20943, showing 5 records out of 104715 total, starting on record 8046, ending on 8050