CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46563  CVE-2010-3979  Candidate  Dswsbobje in SAP BusinessObjects Enterprise XI 3.2 generates different error messages depending on whether the Login field corresponds to a valid username, which allows remote attackers to enumerate account names via a login SOAPAction to the dswsbobje/services/session URI.  Assigned (20101018)  None (candidate not yet proposed)    View
46819  CVE-2010-4235  Candidate  Format string vulnerability in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via vectors related to the x-wap-profile HTTP header.  Assigned (20101111)  None (candidate not yet proposed)    View
47075  CVE-2010-4491  Candidate  Google Chrome before 8.0.552.215 does not properly restrict privileged extensions, which allows remote attackers to cause a denial of service (memory corruption) via a crafted extension.  Assigned (20101207)  None (candidate not yet proposed)    View
47331  CVE-2010-4747  Candidate  Cross-site scripting (XSS) vulnerability in wordpress-processing-embed/data/popup.php in the Processing Embed plugin 0.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the pluginurl parameter.  Assigned (20110301)  None (candidate not yet proposed)    View
47587  CVE-2010-5003  Candidate  SQL injection vulnerability in the AutarTimonial (com_autartimonial) component 1.0.8 for Joomla! allows remote attackers to execute arbitrary SQL commands via the limit parameter in an autartimonial action to index.php. NOTE: some of these details are obtained from third party information.  Assigned (20111101)  None (candidate not yet proposed)    View

Page 18733 of 20943, showing 5 records out of 104715 total, starting on record 93661, ending on 93665

Actions