CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
46577 | CVE-2010-3993 | Candidate | Unspecified vulnerability in HP Insight Control Server Migration before 6.2 allows remote attackers to obtain sensitive information or modify data via unknown vectors. | Assigned (20101018) | None (candidate not yet proposed) | View | |
46833 | CVE-2010-4249 | Candidate | The wait_for_unix_gc function in net/unix/garbage.c in the Linux kernel before 2.6.37-rc3-next-20101125 does not properly select times for garbage collection of inflight sockets, which allows local users to cause a denial of service (system hang) via crafted use of the socketpair and sendmsg system calls for SOCK_SEQPACKET sockets. | Assigned (20101116) | None (candidate not yet proposed) | View | |
47089 | CVE-2010-4505 | Candidate | Multiple SQL injection vulnerabilities in login.php in Injader 2.4.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) un and (2) pw parameters. | Assigned (20101208) | None (candidate not yet proposed) | View | |
47345 | CVE-2010-4761 | Candidate | The customer-interface ticket-print dialog in Open Ticket Request System (OTRS) before 3.0.0-beta3 does not properly restrict customer-visible data, which allows remote authenticated users to obtain potentially sensitive information from the (1) responsible, (2) owner, (3) accounted time, (4) pending until, and (5) lock fields by reading this dialog. | Assigned (20110318) | None (candidate not yet proposed) | View | |
47601 | CVE-2010-5017 | Candidate | SQL injection vulnerability in stats.php in Elite Gaming Ladders 3.0 allows remote attackers to execute arbitrary SQL commands via the account parameter. | Assigned (20111102) | None (candidate not yet proposed) | View |
Page 19205 of 20943, showing 5 records out of 104715 total, starting on record 96021, ending on 96025