CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
45815 | CVE-2010-3231 | Candidate | Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac do not properly validate record information, which allows remote attackers to execute arbitrary code via a crafted Excel document, aka "Excel Record Parsing Memory Corruption Vulnerability." | Assigned (20100903) | None (candidate not yet proposed) | View | |
46071 | CVE-2010-3487 | Candidate | Directory traversal vulnerability in YelloSoft Pinky 1.0 for Windows allows remote attackers to read arbitrary files via a %5C (encoded backslash) in the URL. | Assigned (20100922) | None (candidate not yet proposed) | View | |
46327 | CVE-2010-3743 | Candidate | Directory traversal vulnerability in Visual Synapse HTTP Server 1.0 RC1 through RC3, and 0.60 and earlier, allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | Assigned (20101005) | None (candidate not yet proposed) | View | |
46583 | CVE-2010-3999 | Candidate | gnc-test-env in GnuCash 2.3.15 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | Assigned (20101019) | None (candidate not yet proposed) | View | |
46839 | CVE-2010-4255 | Candidate | The fixup_page_fault function in arch/x86/traps.c in Xen 4.0.1 and earlier on 64-bit platforms, when paravirtualization is enabled, does not verify that kernel mode is used to call the handle_gdt_ldt_mapping_fault function, which allows guest OS users to cause a denial of service (host OS BUG_ON) via a crafted memory access. | Assigned (20101116) | None (candidate not yet proposed) | View |
Page 20292 of 20943, showing 5 records out of 104715 total, starting on record 101456, ending on 101460