CVE List

Id CVE No. Status Description Phase Votes Comments Actions
45803  CVE-2010-3219  Candidate  Array index vulnerability in Microsoft Word 2002 SP3 allows remote attackers to execute arbitrary code via a crafted Word document that triggers memory corruption, aka "Word Index Parsing Vulnerability."  Assigned (20100903)  None (candidate not yet proposed)    View
46059  CVE-2010-3475  Candidate  IBM DB2 9.7 before FP3 does not properly enforce privilege requirements for execution of entries in the dynamic SQL cache, which allows remote authenticated users to bypass intended access restrictions by leveraging the cache to execute an UPDATE statement contained in a compiled compound SQL statement.  Assigned (20100920)  None (candidate not yet proposed)    View
46315  CVE-2010-3731  Candidate  Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP3 allows remote attackers to execute arbitrary code via a long username string.  Assigned (20101005)  None (candidate not yet proposed)    View
46571  CVE-2010-3987  Candidate  Cross-site scripting (XSS) vulnerability in HP Insight Control Virtual Machine Management before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20101018)  None (candidate not yet proposed)    View
46827  CVE-2010-4243  Candidate  fs/exec.c in the Linux kernel before 2.6.37 does not enable the OOM Killer to assess use of stack memory by arrays representing the (1) arguments and (2) environment, which allows local users to cause a denial of service (memory consumption) via a crafted exec system call, aka an "OOM dodging issue," a related issue to CVE-2010-3858.  Assigned (20101116)  None (candidate not yet proposed)    View

Page 19326 of 20943, showing 5 records out of 104715 total, starting on record 96626, ending on 96630

Actions