CVE List

Id CVE No. Status Description Phase Votes Comments Actions
44022  CVE-2010-1438  Candidate  Web Application Finger Printer (WAFP) 0.01-26c3 uses fixed pathnames under /tmp for temporary files and directories, which (1) allows local users to cause a denial of service (application outage) by creating a file with a pathname that the product expects is available for its own internal use, (2) allows local users to overwrite arbitrary files via symlink attacks on certain files in /tmp, (3) might allow local users to delete arbitrary files and directories via a symlink attack on a directory under /tmp, and (4) might make it easier for local users to obtain sensitive information by reading files in a directory under /tmp, related to (a) lib/wafp_pidify.rb, (b) utils/generate_wafp_fingerprint.sh, (c) utils/online_update.sh, and (d) utils/extract_from_db.sh.  Assigned (20100415)  None (candidate not yet proposed)    View
44278  CVE-2010-1694  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20100430)  None (candidate not yet proposed)    View
44534  CVE-2010-1950  Candidate  SQL injection vulnerability in the Online News Paper Manager (com_jnewspaper) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the date_info parameter to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20100518)  None (candidate not yet proposed)    View
44790  CVE-2010-2206  Candidate  Array index error in AcroForm.api in Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allows remote attackers to execute arbitrary code via a crafted GIF image in a PDF file, which bypasses a size check and triggers a heap-based buffer overflow.  Assigned (20100608)  None (candidate not yet proposed)    View
45046  CVE-2010-2462  Candidate  SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL commands via the id parameter in a cancel action.  Assigned (20100625)  None (candidate not yet proposed)    View

Page 20211 of 20943, showing 5 records out of 104715 total, starting on record 101051, ending on 101055

Actions