CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47337  CVE-2010-4753  Candidate  Cross-site scripting (XSS) vulnerability in LightNEasy.php in LightNEasy 3.2.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter, which is not properly handled in a forced SQL error message.  Assigned (20110301)  None (candidate not yet proposed)    View
47593  CVE-2010-5009  Candidate  SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter in a matchp action.  Assigned (20111102)  None (candidate not yet proposed)    View
47849  CVE-2010-5265  Candidate  Untrusted search path vulnerability in SmartSniff 1.71 allows local users to gain privileges via a Trojan horse wpcap.dll file in the current working directory, as demonstrated by a directory that contains a .cfg or .ssp file. NOTE: some of these details are obtained from third party information.  Assigned (20120907)  None (candidate not yet proposed)    View
48105  CVE-2011-0193  Candidate  Multiple buffer overflows in Image RAW in Apple Mac OS X before 10.6.7 allow remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted Canon RAW image.  Assigned (20101223)  None (candidate not yet proposed)    View
48361  CVE-2011-0449  Candidate  actionpack/lib/action_view/template/resolver.rb in Ruby on Rails 3.0.x before 3.0.4, when a case-insensitive filesystem is used, does not properly implement filters associated with the list of available templates, which allows remote attackers to bypass intended access restrictions via an action name that uses an unintended case for alphabetic characters.  Assigned (20110113)  None (candidate not yet proposed)    View

Page 19167 of 20943, showing 5 records out of 104715 total, starting on record 95831, ending on 95835

Actions