CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46575  CVE-2010-3991  Candidate  Cross-site scripting (XSS) vulnerability in HP Insight Control Server Migration before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20101018)  None (candidate not yet proposed)    View
46831  CVE-2010-4247  Candidate  The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18, and possibly other versions, allows guest OS users to cause a denial of service (infinite loop and CPU consumption) via a large production request index to the blkback or blktap back-end drivers. NOTE: some of these details are obtained from third party information.  Assigned (20101116)  None (candidate not yet proposed)    View
47087  CVE-2010-4503  Candidate  SQL injection vulnerability in indexlight.php in Aigaion 1.3.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter in an export action.  Assigned (20101208)  None (candidate not yet proposed)    View
47343  CVE-2010-4759  Candidate  Open Ticket Request System (OTRS) before 3.0.0-beta7 does not properly restrict the ticket ages that are within the scope of a search, which allows remote authenticated users to cause a denial of service (daemon hang) via a fulltext search.  Assigned (20110318)  None (candidate not yet proposed)    View
47599  CVE-2010-5015  Candidate  SQL injection vulnerability in view_photo.php in 2daybiz Network Community Script allows remote attackers to execute arbitrary SQL commands via the alb parameter.  Assigned (20111102)  None (candidate not yet proposed)    View

Page 19647 of 20943, showing 5 records out of 104715 total, starting on record 98231, ending on 98235

Actions