CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47344  CVE-2010-4760  Candidate  Open Ticket Request System (OTRS) before 3.0.0-beta6 adds email-notification-ext articles to tickets during processing of event-based notifications, which allows remote authenticated users to obtain potentially sensitive information by reading a ticket.  Assigned (20110318)  None (candidate not yet proposed)    View
47600  CVE-2010-5016  Candidate  SQL injection vulnerability in matchdb.php in Elite Gaming Ladders 3.5 and earlier allows remote attackers to execute arbitrary SQL commands via the match parameter.  Assigned (20111102)  None (candidate not yet proposed)    View
47856  CVE-2010-5272  Candidate  Untrusted search path vulnerability in Altova DatabaseSpy 2011 Enterprise Edition SP1 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .qprj file. NOTE: some of these details are obtained from third party information.  Assigned (20120907)  None (candidate not yet proposed)    View
48112  CVE-2011-0200  Candidate  Integer overflow in ColorSync in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via an image containing a crafted embedded ColorSync profile that triggers a heap-based buffer overflow.  Assigned (20101223)  None (candidate not yet proposed)    View
48368  CVE-2011-0456  Candidate  webscript.pl in Open Ticket Request System (OTRS) 2.3.4 and earlier allows remote attackers to execute arbitrary commands via unspecified vectors, related to a "command injection vulnerability."  Assigned (20110114)  None (candidate not yet proposed)    View

Page 19728 of 20943, showing 5 records out of 104715 total, starting on record 98636, ending on 98640

Actions