CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46334  CVE-2010-3750  Candidate  rjrmrpln.dll in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly validate file contents that are used during interaction with a heap buffer, which allows remote attackers to execute arbitrary code via crafted Name Value Property (NVP) elements in logical streams in a media file.  Assigned (20101005)  None (candidate not yet proposed)    View
46590  CVE-2010-4006  Candidate  Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter.  Assigned (20101020)  None (candidate not yet proposed)    View
46846  CVE-2010-4262  Candidate  Stack-based buffer overflow in Xfig 3.2.4 and 3.2.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a FIG image with a crafted color definition.  Assigned (20101116)  None (candidate not yet proposed)    View
47102  CVE-2010-4518  Candidate  Cross-site scripting (XSS) vulnerability in wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the v1 parameter.  Assigned (20101209)  None (candidate not yet proposed)    View
47358  CVE-2010-4774  Candidate  SQL injection vulnerability in pdf.php in AuraCMS 1.62 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-4804 and CVE-2007-4171.  Assigned (20110323)  None (candidate not yet proposed)    View

Page 19692 of 20943, showing 5 records out of 104715 total, starting on record 98456, ending on 98460

Actions