CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
45028 | CVE-2010-2444 | Candidate | parse/Csv2_parse.c in MaraDNS 1.3.03, and other versions before 1.4.03, does not properly handle hostnames that do not end in a "." (dot) character, which allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted csv2 zone file. | Assigned (20100624) | None (candidate not yet proposed) | View | |
45284 | CVE-2010-2700 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allows remote attackers to inject arbitrary web script or HTML via the search parameter. | Assigned (20100712) | None (candidate not yet proposed) | View | |
45540 | CVE-2010-2956 | Candidate | Sudo 1.7.0 through 1.7.4p3, when a Runas group is configured, does not properly handle use of the -u option in conjunction with the -g option, which allows local users to gain privileges via a command line containing a "-u root" sequence. | Assigned (20100804) | None (candidate not yet proposed) | View | |
45796 | CVE-2010-3212 | Candidate | SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL commands via the frmQuestion parameter in a retrieve action, in conjunction with a user/password PATH_INFO. | Assigned (20100903) | None (candidate not yet proposed) | View | |
46052 | CVE-2010-3468 | Candidate | Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CMS 5 through 5.2, allows remote attackers to read arbitrary files via a .. (dot dot) in the FILEID parameter to the default URI under tasks/render/file/. | Assigned (20100920) | None (candidate not yet proposed) | View |
Page 18763 of 20943, showing 5 records out of 104715 total, starting on record 93811, ending on 93815