CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42233  CVE-2009-4798  Candidate  Multiple SQL injection vulnerabilities in Diskos CMS 6.x allow remote attackers to execute arbitrary SQL commands via the (1) kat parameter to side.asp, and the (2) brugerid and (3) password fields to the administration login feature.  Assigned (20100422)  None (candidate not yet proposed)    View
42489  CVE-2009-5054  Candidate  Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations.  Assigned (20110203)  None (candidate not yet proposed)    View
42745  CVE-2010-0161  Candidate  The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 on Windows Vista, Windows Server 2008 R2, and Windows 7 allows remote SMTP, IMAP, and POP servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via crafted data in a session that uses SSPI.  Assigned (20100106)  None (candidate not yet proposed)    View
43001  CVE-2010-0417  Candidate  Buffer overflow in common/util/rlstate.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a RuleBook structure with a large number of rule-separator characters that trigger heap memory corruption.  Assigned (20100127)  None (candidate not yet proposed)    View
43257  CVE-2010-0673  Candidate  SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress allows remote attackers to execute arbitrary SQL commands via the postid parameter.  Assigned (20100222)  None (candidate not yet proposed)    View

Page 20427 of 20943, showing 5 records out of 104715 total, starting on record 102131, ending on 102135

Actions