CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46840  CVE-2010-4256  Candidate  The pipe_fcntl function in fs/pipe.c in the Linux kernel before 2.6.37 does not properly determine whether a file is a named pipe, which allows local users to cause a denial of service via an F_SETPIPE_SZ fcntl call.  Assigned (20101116)  None (candidate not yet proposed)    View
47096  CVE-2010-4512  Candidate  Cobbler before 2.0.4 uses an incorrect umask value, which allows local users to have an unspecified impact by leveraging world writable permissions for files and directories.  Assigned (20101209)  None (candidate not yet proposed)    View
47352  CVE-2010-4768  Candidate  Open Ticket Request System (OTRS) before 2.3.5 does not properly disable hidden permissions, which allows remote authenticated users to bypass intended queue access restrictions in opportunistic circumstances by visiting a ticket, related to a certain ordering of permission-set and permission-remove operations involving both hidden permissions and other permissions.  Assigned (20110318)  None (candidate not yet proposed)    View
47608  CVE-2010-5024  Candidate  SQL injection vulnerability in manage/add_user.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote authenticated users, with Read privileges, to execute arbitrary SQL commands via the user_id parameter. NOTE: some of these details are obtained from third party information.  Assigned (20111102)  None (candidate not yet proposed)    View
47864  CVE-2010-5280  Candidate  Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 for Joomla! allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the tabname parameter in a userProfile action to index.php. NOTE: this can be leveraged to execute arbitrary code by using the file upload feature.  Assigned (20121126)  None (candidate not yet proposed)    View

Page 20372 of 20943, showing 5 records out of 104715 total, starting on record 101856, ending on 101860

Actions