CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
47344 | CVE-2010-4760 | Candidate | Open Ticket Request System (OTRS) before 3.0.0-beta6 adds email-notification-ext articles to tickets during processing of event-based notifications, which allows remote authenticated users to obtain potentially sensitive information by reading a ticket. | Assigned (20110318) | None (candidate not yet proposed) | View | |
47600 | CVE-2010-5016 | Candidate | SQL injection vulnerability in matchdb.php in Elite Gaming Ladders 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the match parameter. | Assigned (20111102) | None (candidate not yet proposed) | View | |
47856 | CVE-2010-5272 | Candidate | Untrusted search path vulnerability in Altova DatabaseSpy 2011 Enterprise Edition SP1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .qprj file. NOTE: some of these details are obtained from third party information. | Assigned (20120907) | None (candidate not yet proposed) | View | |
48112 | CVE-2011-0200 | Candidate | Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image containing a crafted embedded ColorSync profile that triggers a heap-based buffer overflow. | Assigned (20101223) | None (candidate not yet proposed) | View | |
48368 | CVE-2011-0456 | Candidate | webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability." | Assigned (20110114) | None (candidate not yet proposed) | View |
Page 19728 of 20943, showing 5 records out of 104715 total, starting on record 98636, ending on 98640