CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
45047 | CVE-2010-2463 | Candidate | Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrary web script or HTML via the post_id parameter in a modify action. | Assigned (20100625) | None (candidate not yet proposed) | View | |
45303 | CVE-2010-2719 | Candidate | SQL injection vulnerability in show.php in phpaaCms 0.3.1 UTF-8, and possibly other versions, allows remote attackers to execute arbitrary SQL commands via the id parameter. | Assigned (20100713) | None (candidate not yet proposed) | View | |
45559 | CVE-2010-2975 | Candidate | Cisco Unified Wireless Network (UWN) Solution 7.x through 7.0.98.0 does not properly handle multiple SSH sessions, which allows physically proximate attackers to read a password, related to an "arrow key failure," aka Bug ID CSCtg51544. | Assigned (20100809) | None (candidate not yet proposed) | View | |
45815 | CVE-2010-3231 | Candidate | Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel Record Parsing Memory Corruption Vulnerability." | Assigned (20100903) | None (candidate not yet proposed) | View | |
46071 | CVE-2010-3487 | Candidate | Directory traversal vulnerability in YelloSoft Pinky 1.0 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the URL. | Assigned (20100922) | None (candidate not yet proposed) | View |
Page 20286 of 20943, showing 5 records out of 104715 total, starting on record 101426, ending on 101430