CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46327  CVE-2010-3743  Candidate  Directory traversal vulnerability in Visual Synapse HTTP Server 1.0 RC1 through RC3, and 0.60 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.  Assigned (20101005)  None (candidate not yet proposed)    View
46583  CVE-2010-3999  Candidate  gnc-test-env in GnuCash 2.3.15 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.  Assigned (20101019)  None (candidate not yet proposed)    View
46839  CVE-2010-4255  Candidate  The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when paravirtualization is enabled, does not verify that kernel mode is used to call the handle_gdt_ldt_mapping_fault function, which allows guest OS users to cause a denial of service (host OS BUG_ON) via a crafted memory access.  Assigned (20101116)  None (candidate not yet proposed)    View
47095  CVE-2010-4511  Candidate  Unspecified vulnerability in Movable Type 4.x before 4.35 and 5.x before 5.04 has unknown impact and attack vectors related to the "dynamic publishing error message."  Assigned (20101209)  None (candidate not yet proposed)    View
47351  CVE-2010-4767  Candidate  Open Ticket Request System (OTRS) before 2.3.6 does not properly handle e-mail messages in which the From line contains UTF-8 characters associated with diacritical marks and an invalid charset, which allows remote attackers to cause a denial of service (duplicate tickets and duplicate auto-responses) by sending a crafted message to a POP3 mailbox.  Assigned (20110318)  None (candidate not yet proposed)    View

Page 20287 of 20943, showing 5 records out of 104715 total, starting on record 101431, ending on 101435

Actions