CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46319  CVE-2010-3735  Candidate  The "Query Compiler, Rewrite, Optimizer" component in IBM DB2 UDB 9.5 before FP6a allows remote authenticated users to cause a denial of service (CPU consumption) via a crafted query involving certain UNION ALL views, leading to an indefinitely large amount of compilation time.  Assigned (20101005)  None (candidate not yet proposed)    View
46575  CVE-2010-3991  Candidate  Cross-site scripting (XSS) vulnerability in HP Insight Control Server Migration before 6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20101018)  None (candidate not yet proposed)    View
46831  CVE-2010-4247  Candidate  The do_block_io_op function in (1) drivers/xen/blkback/blkback.c and (2) drivers/xen/blktap/blktap.c in Xen before 3.4.0 for the Linux kernel 2.6.18, and possibly other versions, allows guest OS users to cause a denial of service (infinite loop and CPU consumption) via a large production request index to the blkback or blktap back-end drivers. NOTE: some of these details are obtained from third party information.  Assigned (20101116)  None (candidate not yet proposed)    View
47087  CVE-2010-4503  Candidate  SQL injection vulnerability in indexlight.php in Aigaion 1.3.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter in an export action.  Assigned (20101208)  None (candidate not yet proposed)    View
47343  CVE-2010-4759  Candidate  Open Ticket Request System (OTRS) before 3.0.0-beta7 does not properly restrict the ticket ages that are within the scope of a search, which allows remote authenticated users to cause a denial of service (daemon hang) via a fulltext search.  Assigned (20110318)  None (candidate not yet proposed)    View

Page 19656 of 20943, showing 5 records out of 104715 total, starting on record 98276, ending on 98280

Actions