CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
42987 | CVE-2010-0403 | Candidate | Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the app parameter. | Assigned (20100127) | None (candidate not yet proposed) | View | |
43243 | CVE-2010-0659 | Candidate | The image decoder in WebKit before r52833, as used in Google Chrome before 4.0.249.78, does not properly handle a failure of memory allocation, which allows remote attackers to execute arbitrary code in the Chrome sandbox via a malformed GIF file that specifies a large size. | Assigned (20100218) | None (candidate not yet proposed) | View | |
43499 | CVE-2010-0915 | Candidate | Unspecified vulnerability in the Oracle Advanced Product Catalog component in Oracle E-Business Suite 11.5.10.2, 12.0.6, and 12.1.2 allows remote authenticated users to affect confidentiality and integrity via unknown vectors. | Assigned (20100303) | None (candidate not yet proposed) | View | |
43755 | CVE-2010-1171 | Candidate | Red Hat Network (RHN) Satellite 5.3 and 5.4 exposes a dangerous, obsolete XML-RPC API, which allows remote authenticated users to access arbitrary files and cause a denial of service (failed yum operations) via vectors related to configuration and package group (comps.xml) files for channels. | Assigned (20100329) | None (candidate not yet proposed) | View | |
44011 | CVE-2010-1427 | Candidate | Cross-site scripting (XSS) vulnerability in the SearchHighlight plugin in MODx Evolution before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors related to AjaxSearch. | Assigned (20100415) | None (candidate not yet proposed) | View |
Page 19348 of 20943, showing 5 records out of 104715 total, starting on record 96736, ending on 96740