CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47125  CVE-2010-4541  Candidate  Stack-based buffer overflow in the loadit function in plug-ins/common/sphere-designer.c in the SPHERE DESIGNER plugin in GIMP 2.6.11 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long "Number of lights" field in a plugin configuration file. NOTE: it may be uncommon to obtain a GIMP plugin configuration file from an untrusted source that is separate from the distribution of the plugin itself.  Assigned (20101209)  None (candidate not yet proposed)    View
47381  CVE-2010-4797  Candidate  Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.  Assigned (20110426)  None (candidate not yet proposed)    View
47637  CVE-2010-5053  Candidate  SQL injection vulnerability in the XOBBIX (com_xobbix) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the prodid parameter in a prod_desc action to index.php.  Assigned (20111122)  None (candidate not yet proposed)    View
47893  CVE-2010-5309  Candidate  GE Healthcare CADStream Server has a default password of confirma for the admin user, which has unspecified impact and attack vectors.  Assigned (20140929)  None (candidate not yet proposed)    View
48149  CVE-2011-0237  Candidate  WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.  Assigned (20101223)  None (candidate not yet proposed)    View

Page 1758 of 20943, showing 5 records out of 104715 total, starting on record 8786, ending on 8790

Actions