CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42466  CVE-2009-5031  Candidate  ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header.  Assigned (20101209)  None (candidate not yet proposed)    View
42722  CVE-2010-0138  Candidate  Buffer overflow in Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 and earlier on Windows, as distributed in CiscoWorks LAN Management Solution (LMS), allows remote attackers to execute arbitrary code via a malformed getProcessName CORBA General Inter-ORB Protocol (GIOP) request, related to a "third-party component," aka Bug ID CSCsv62350.  Assigned (20100104)  None (candidate not yet proposed)    View
42978  CVE-2010-0394  Candidate  PyGIT.py in the Trac Git plugin (trac-git) before 0.0.20080710-3+lenny1 and before 0.0.20090320-1 on Debian GNU/Linux, when enabled in Trac, allows remote attackers to execute arbitrary commands via shell metacharacters in a crafted HTTP query that is used to generate a certain git command.  Assigned (20100127)  None (candidate not yet proposed)    View
43234  CVE-2010-0650  Candidate  WebKit, as used in Google Chrome before 4.0.249.78 and Apple Safari, allows remote attackers to bypass intended restrictions on popup windows via crafted use of a mouse click event.  Assigned (20100218)  None (candidate not yet proposed)    View
43490  CVE-2010-0906  Candidate  Unspecified vulnerability in Oracle Secure Backup 10.3.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.  Assigned (20100303)  None (candidate not yet proposed)    View

Page 18619 of 20943, showing 5 records out of 104715 total, starting on record 93091, ending on 93095

Actions