CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47090  CVE-2010-4506  Candidate  Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is reachable from the "Certificate Export" wizard.  Assigned (20101208)  None (candidate not yet proposed)    View
47346  CVE-2010-4762  Candidate  Cross-site scripting (XSS) vulnerability in the rich-text-editor component in Open Ticket Request System (OTRS) before 3.0.0-beta2 allows remote authenticated users to inject arbitrary web script or HTML by using the "source code" feature in the customer interface.  Assigned (20110318)  None (candidate not yet proposed)    View
47602  CVE-2010-5018  Candidate  Cross-site scripting (XSS) vulnerability in products/classified/headersearch.php in 2daybiz Online Classified Script allows remote attackers to inject arbitrary web script or HTML via the sid parameter.  Assigned (20111102)  None (candidate not yet proposed)    View
47858  CVE-2010-5274  Candidate  Untrusted search path vulnerability in PKZIP before 12.50.0014 allows local users to gain privileges via a Trojan horse dwmapi.dll file in the current working directory, as demonstrated by a directory that contains a .zip file. NOTE: some of these details are obtained from third party information.  Assigned (20120907)  None (candidate not yet proposed)    View
48114  CVE-2011-0202  Candidate  Integer overflow in CoreGraphics in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted embedded Type 1 font in a PDF document.  Assigned (20101223)  None (candidate not yet proposed)    View

Page 19888 of 20943, showing 5 records out of 104715 total, starting on record 99436, ending on 99440

Actions