CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
46583 | CVE-2010-3999 | Candidate | gnc-test-env in GnuCash 2.3.15 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | Assigned (20101019) | None (candidate not yet proposed) | View | |
46839 | CVE-2010-4255 | Candidate | The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when paravirtualization is enabled, does not verify that kernel mode is used to call the handle_gdt_ldt_mapping_fault function, which allows guest OS users to cause a denial of service (host OS BUG_ON) via a crafted memory access. | Assigned (20101116) | None (candidate not yet proposed) | View | |
47095 | CVE-2010-4511 | Candidate | Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic publishing error message." | Assigned (20101209) | None (candidate not yet proposed) | View | |
47351 | CVE-2010-4767 | Candidate | Open Ticket Request System (OTRS) before 2.3.6 does not properly handle e-mail messages in which the From line contains UTF-8 characters associated with diacritical marks and an invalid charset, which allows remote attackers to cause a denial of service (duplicate tickets and duplicate auto-responses) by sending a crafted message to a POP3 mailbox. | Assigned (20110318) | None (candidate not yet proposed) | View | |
47607 | CVE-2010-5023 | Candidate | SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intDivisionID parameter. | Assigned (20111102) | None (candidate not yet proposed) | View |
Page 19682 of 20943, showing 5 records out of 104715 total, starting on record 98406, ending on 98410