CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46068  CVE-2010-3484  Candidate  SQL injection vulnerability in common.php in LightNEasy 3.2.1 allows remote attackers to execute arbitrary SQL commands via the handle parameter to LightNEasy.php, a different vector than CVE-2008-6593.  Assigned (20100922)  None (candidate not yet proposed)    View
46324  CVE-2010-3740  Candidate  The Net Search Extender (NSE) implementation in the Text Search component in IBM DB2 UDB 9.5 before FP6a does not properly handle an alphanumeric Fuzzy search, which allows remote authenticated users to cause a denial of service (memory consumption and system hang) via the db2ext.textSearch function.  Assigned (20101005)  None (candidate not yet proposed)    View
46580  CVE-2010-3996  Candidate  festival_server in Centre for Speech Technology Research (CSTR) Festival, probably 2.0.95-beta and earlier, places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.  Assigned (20101019)  None (candidate not yet proposed)    View
46836  CVE-2010-4252  Candidate  OpenSSL before 1.0.0c, when J-PAKE is enabled, does not properly validate the public parameters in the J-PAKE protocol, which allows remote attackers to bypass the need for knowledge of the shared secret, and successfully authenticate, by sending crafted values in each round of the protocol.  Assigned (20101116)  None (candidate not yet proposed)    View
47092  CVE-2010-4508  Candidate  The WebSockets implementation in Mozilla Firefox 4 through 4.0 Beta 7 does not properly perform proxy upgrade negotiation, which has unspecified impact and remote attack vectors, related to an "inherent problem" with the WebSocket specification.  Assigned (20101209)  None (candidate not yet proposed)    View

Page 20047 of 20943, showing 5 records out of 104715 total, starting on record 100231, ending on 100235

Actions