CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42219  CVE-2009-4784  Candidate  SQL injection vulnerability in the Joaktree (com_joaktree) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the treeId parameter to index.php.  Assigned (20100421)  None (candidate not yet proposed)    View
42475  CVE-2009-5040  Candidate  CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555.  Assigned (20110107)  None (candidate not yet proposed)    View
42731  CVE-2010-0147  Candidate  SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117, 5.2 before 5.2.0.296, and 6.0 before 6.0.1.132 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.  Assigned (20100104)  None (candidate not yet proposed)    View
42987  CVE-2010-0403  Candidate  Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the app parameter.  Assigned (20100127)  None (candidate not yet proposed)    View
43243  CVE-2010-0659  Candidate  The image decoder in WebKit before r52833, as used in Google Chrome before 4.0.249.78, does not properly handle a failure of memory allocation, which allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed GIF file that specifies a large size.  Assigned (20100218)  None (candidate not yet proposed)    View

Page 18724 of 20943, showing 5 records out of 104715 total, starting on record 93616, ending on 93620

Actions