CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47350  CVE-2010-4766  Candidate  The AgentTicketForward feature in Open Ticket Request System (OTRS) before 2.4.7 does not properly remove inline images from HTML e-mail messages, which allows remote attackers to obtain potentially sensitive image information in opportunistic circumstances by reading a forwarded message in a standard e-mail client.  Assigned (20110318)  None (candidate not yet proposed)    View
47606  CVE-2010-5022  Candidate  SQL injection vulnerability in the JExtensions JE Story Submit (com_jesubmit) component 1.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the view parameter to index.php.  Assigned (20111102)  None (candidate not yet proposed)    View
47862  CVE-2010-5278  Candidate  Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possibly earlier, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the class_key parameter. NOTE: some of these details are obtained from third party information.  Assigned (20121007)  None (candidate not yet proposed)    View
48118  CVE-2011-0206  Candidate  Buffer overflow in International Components for Unicode (ICU) in Apple Mac OS X before 10.6.8 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via vectors involving uppercase strings.  Assigned (20101223)  None (candidate not yet proposed)    View
48374  CVE-2011-0462  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the login page in the webui component in SUSE openSUSE Build Service (OBS) before 2.1.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20110114)  None (candidate not yet proposed)    View

Page 20208 of 20943, showing 5 records out of 104715 total, starting on record 101036, ending on 101040

Actions