CVE List

Id CVE No. Status Description Phase Votes Comments Actions
45297  CVE-2010-2713  Candidate  The vte_sequence_handler_window_manipulation function in vteseq.c in libvte (aka libvte9) in VTE 0.25.1 and earlier, as used in gnome-terminal, does not properly handle escape sequences, which allows remote attackers to execute arbitrary commands or obtain potentially sensitive information via a (1) window title or (2) icon title sequence. NOTE: this issue exists because of a CVE-2003-0070 regression.  Assigned (20100713)  None (candidate not yet proposed)    View
45553  CVE-2010-2969  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in MoinMoin 1.7.3 and earlier, and 1.9.x before 1.9.3, allow remote attackers to inject arbitrary web script or HTML via crafted content, related to (1) action/LikePages.py, (2) action/chart.py, and (3) action/userprofile.py, a similar issue to CVE-2010-2487.  Assigned (20100804)  None (candidate not yet proposed)    View
45809  CVE-2010-3225  Candidate  Use-after-free vulnerability in the Media Player Network Sharing Service in Microsoft Windows Vista SP1 and SP2 and Windows 7 allows remote attackers to execute arbitrary code via a crafted Real Time Streaming Protocol (RTSP) packet, aka "RTSP Use After Free Vulnerability."  Assigned (20100903)  None (candidate not yet proposed)    View
46065  CVE-2010-3481  Candidate  Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) user_name and (2) password variables, possibly related to include/classes/Login.php. NOTE: some of these details are obtained from third party information. NOTE: the password vector might not be vulnerable.  Assigned (20100922)  None (candidate not yet proposed)    View
46321  CVE-2010-3737  Candidate  Memory leak in the Relational Data Services component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (heap memory consumption) by executing a (1) user-defined function (UDF) or (2) stored procedure while using a different code page than the database server.  Assigned (20101005)  None (candidate not yet proposed)    View

Page 19204 of 20943, showing 5 records out of 104715 total, starting on record 96016, ending on 96020

Actions