CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46583  CVE-2010-3999  Candidate  gnc-test-env in GnuCash 2.3.15 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.  Assigned (20101019)  None (candidate not yet proposed)    View
46839  CVE-2010-4255  Candidate  The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when paravirtualization is enabled, does not verify that kernel mode is used to call the handle_gdt_ldt_mapping_fault function, which allows guest OS users to cause a denial of service (host OS BUG_ON) via a crafted memory access.  Assigned (20101116)  None (candidate not yet proposed)    View
47095  CVE-2010-4511  Candidate  Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic publishing error message."  Assigned (20101209)  None (candidate not yet proposed)    View
47351  CVE-2010-4767  Candidate  Open Ticket Request System (OTRS) before 2.3.6 does not properly handle e-mail messages in which the From line contains UTF-8 characters associated with diacritical marks and an invalid charset, which allows remote attackers to cause a denial of service (duplicate tickets and duplicate auto-responses) by sending a crafted message to a POP3 mailbox.  Assigned (20110318)  None (candidate not yet proposed)    View
47607  CVE-2010-5023  Candidate  SQL injection vulnerability in index.asp in Digital Interchange Calendar 5.8.5 allows remote attackers to execute arbitrary SQL commands via the intDivisionID parameter.  Assigned (20111102)  None (candidate not yet proposed)    View

Page 19682 of 20943, showing 5 records out of 104715 total, starting on record 98406, ending on 98410

Actions