CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47608  CVE-2010-5024  Candidate  SQL injection vulnerability in manage/add_user.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote authenticated users, with Read privileges, to execute arbitrary SQL commands via the user_id parameter. NOTE: some of these details are obtained from third party information.  Assigned (20111102)  None (candidate not yet proposed)    View
47864  CVE-2010-5280  Candidate  Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabname parameter in a userProfile action to index.php. NOTE: this can be leveraged to execute arbitrary code by using the file upload feature.  Assigned (20121126)  None (candidate not yet proposed)    View
48120  CVE-2011-0208  Candidate  QuickLook in Apple Mac OS X 10.6 before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted Microsoft Office document.  Assigned (20101223)  None (candidate not yet proposed)    View
48376  CVE-2011-0464  Candidate  Unspecified vulnerability in Novell Vibe OnPrem 3.0 before Hot Patch 1 allows remote attackers to execute arbitrary code via unknown vectors.  Assigned (20110114)  None (candidate not yet proposed)    View
48632  CVE-2011-0720  Candidate  Unspecified vulnerability in Plone 2.5 through 4.0, as used in Conga, luci, and possibly other products, allows remote attackers to obtain administrative access, read or create arbitrary content, and change the site skin via unknown vectors.  Assigned (20110131)  None (candidate not yet proposed)    View

Page 20354 of 20943, showing 5 records out of 104715 total, starting on record 101766, ending on 101770

Actions