CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
47125 | CVE-2010-4541 | Candidate | Stack-based buffer overflow in the loadit function in plug-ins/common/sphere-designer.c in the SPHERE DESIGNER plugin in GIMP 2.6.11 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long "Number of lights" field in a plugin configuration file. NOTE: it may be uncommon to obtain a GIMP plugin configuration file from an untrusted source that is separate from the distribution of the plugin itself. | Assigned (20101209) | None (candidate not yet proposed) | View | |
47381 | CVE-2010-4797 | Candidate | Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields. | Assigned (20110426) | None (candidate not yet proposed) | View | |
47637 | CVE-2010-5053 | Candidate | SQL injection vulnerability in the XOBBIX (com_xobbix) component 1.0.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the prodid parameter in a prod_desc action to index.php. | Assigned (20111122) | None (candidate not yet proposed) | View | |
47893 | CVE-2010-5309 | Candidate | GE Healthcare CADStream Server has a default password of confirma for the admin user, which has unspecified impact and attack vectors. | Assigned (20140929) | None (candidate not yet proposed) | View | |
48149 | CVE-2011-0237 | Candidate | WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1. | Assigned (20101223) | None (candidate not yet proposed) | View |
Page 1758 of 20943, showing 5 records out of 104715 total, starting on record 8786, ending on 8790