CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46830  CVE-2010-4246  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in graph.php in pfSense 1.2.3 and 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via the (1) ifnum or (2) ifname parameter, a different vulnerability than CVE-2008-1182.  Assigned (20101116)  None (candidate not yet proposed)    View
47086  CVE-2010-4502  Candidate  Integer overflow in KmxSbx.sys 6.2.0.22 in CA Internet Security Suite Plus 2010 allows local users to cause a denial of service (pool corruption) and execute arbitrary code via crafted arguments to the 0x88000080 IOCTL, which triggers a buffer overflow.  Assigned (20101208)  None (candidate not yet proposed)    View
47342  CVE-2010-4758  Candidate  installer.pl in Open Ticket Request System (OTRS) before 3.0.3 has an Inbound Mail Password field that uses the text type, instead of the password type, for its INPUT element, which makes it easier for physically proximate attackers to obtain the password by reading the workstation screen.  Assigned (20110318)  None (candidate not yet proposed)    View
47598  CVE-2010-5014  Candidate  SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQL commands via the ladder[id] parameter.  Assigned (20111102)  None (candidate not yet proposed)    View
47854  CVE-2010-5270  Candidate  Multiple untrusted search path vulnerabilities in Adobe Device Central CS4 2.0.0 0476 allow local users to gain privileges via a Trojan horse (1) ibfs32.dll or (2) amt_cdb.dll file in the current working directory, as demonstrated by a directory that contains a .adcp file. NOTE: some of these details are obtained from third party information.  Assigned (20120907)  None (candidate not yet proposed)    View

Page 18966 of 20943, showing 5 records out of 104715 total, starting on record 94826, ending on 94830

Actions