CVE List

Id CVE No. Status Description Phase Votes Comments Actions
45028  CVE-2010-2444  Candidate  parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted csv2 zone file.  Assigned (20100624)  None (candidate not yet proposed)    View
45284  CVE-2010-2700  Candidate  Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to inject arbitrary web script or HTML via the search parameter.  Assigned (20100712)  None (candidate not yet proposed)    View
45540  CVE-2010-2956  Candidate  Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence.  Assigned (20100804)  None (candidate not yet proposed)    View
45796  CVE-2010-3212  Candidate  SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via the frmQuestion parameter in a retrieve action, in conjunction with a user/password PATH_INFO.  Assigned (20100903)  None (candidate not yet proposed)    View
46052  CVE-2010-3468  Candidate  Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CMS 5 through 5.2, allows remote attackers to read arbitrary files via a .. (dot dot) in the FILEID parameter to the default URI under tasks/render/file/.  Assigned (20100920)  None (candidate not yet proposed)    View

Page 18763 of 20943, showing 5 records out of 104715 total, starting on record 93811, ending on 93815

Actions