CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
47337 | CVE-2010-4753 | Candidate | Cross-site scripting (XSS) vulnerability in LightNEasy.php in LightNEasy 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, which is not properly handled in a forced SQL error message. | Assigned (20110301) | None (candidate not yet proposed) | View | |
47593 | CVE-2010-5009 | Candidate | SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter in a matchp action. | Assigned (20111102) | None (candidate not yet proposed) | View | |
47849 | CVE-2010-5265 | Candidate | Untrusted search path vulnerability in SmartSniff 1.71 allows local users to gain privileges via a Trojan horse wpcap.dll file in the current working directory, as demonstrated by a directory that contains a .cfg or .ssp file. NOTE: some of these details are obtained from third party information. | Assigned (20120907) | None (candidate not yet proposed) | View | |
48105 | CVE-2011-0193 | Candidate | Multiple buffer overflows in Image RAW in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Canon RAW image. | Assigned (20101223) | None (candidate not yet proposed) | View | |
48361 | CVE-2011-0449 | Candidate | actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters. | Assigned (20110113) | None (candidate not yet proposed) | View |
Page 19167 of 20943, showing 5 records out of 104715 total, starting on record 95831, ending on 95835