CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46833  CVE-2010-4249  Candidate  The wait_for_unix_gc function in net/unix/garbage.c in the Linux kernel before 2.6.37-rc3-next-20101125 does not properly select times for garbage collection of inflight sockets, which allows local users to cause a denial of service (system hang) via crafted use of the socketpair and sendmsg system calls for SOCK_SEQPACKET sockets.  Assigned (20101116)  None (candidate not yet proposed)    View
47089  CVE-2010-4505  Candidate  Multiple SQL injection vulnerabilities in login.php in Injader 2.4.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) un and (2) pw parameters.  Assigned (20101208)  None (candidate not yet proposed)    View
47345  CVE-2010-4761  Candidate  The customer-interface ticket-print dialog in Open Ticket Request System (OTRS) before 3.0.0-beta3 does not properly restrict customer-visible data, which allows remote authenticated users to obtain potentially sensitive information from the (1) responsible, (2) owner, (3) accounted time, (4) pending until, and (5) lock fields by reading this dialog.  Assigned (20110318)  None (candidate not yet proposed)    View
47601  CVE-2010-5017  Candidate  SQL injection vulnerability in stats.php in Elite Gaming Ladders 3.0 allows remote attackers to execute arbitrary SQL commands via the account parameter.  Assigned (20111102)  None (candidate not yet proposed)    View
47857  CVE-2010-5273  Candidate  Untrusted search path vulnerability in Altova DiffDog 2011 Enterprise Edition SP1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .dbdif file. NOTE: some of these details are obtained from third party information.  Assigned (20120907)  None (candidate not yet proposed)    View

Page 18690 of 20943, showing 5 records out of 104715 total, starting on record 93446, ending on 93450

Actions