CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
46334 | CVE-2010-3750 | Candidate | rjrmrpln.dll in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterprise 2.1.2 does not properly validate file contents that are used during interaction with a heap buffer, which allows remote attackers to execute arbitrary code via crafted Name Value Property (NVP) elements in logical streams in a media file. | Assigned (20101005) | None (candidate not yet proposed) | View | |
46590 | CVE-2010-4006 | Candidate | Multiple SQL injection vulnerabilities in search.php in WSN Links 5.0.x before 5.0.81, 5.1.x before 5.1.51, and 6.0.x before 6.0.1 allow remote attackers to execute arbitrary SQL commands via the (1) namecondition or (2) namesearch parameter. | Assigned (20101020) | None (candidate not yet proposed) | View | |
46846 | CVE-2010-4262 | Candidate | Stack-based buffer overflow in Xfig 3.2.4 and 3.2.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a FIG image with a crafted color definition. | Assigned (20101116) | None (candidate not yet proposed) | View | |
47102 | CVE-2010-4518 | Candidate | Cross-site scripting (XSS) vulnerability in wp-safe-search/wp-safe-search-jx.php in the Safe Search plugin 0.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the v1 parameter. | Assigned (20101209) | None (candidate not yet proposed) | View | |
47358 | CVE-2010-4774 | Candidate | SQL injection vulnerability in pdf.php in AuraCMS 1.62 allows remote attackers to execute arbitrary SQL commands via the id parameter, a different vector than CVE-2007-4804 and CVE-2007-4171. | Assigned (20110323) | None (candidate not yet proposed) | View |
Page 19692 of 20943, showing 5 records out of 104715 total, starting on record 98456, ending on 98460