CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
42489 | CVE-2009-5054 | Candidate | Smarty before 3.0.0 beta 4 does not consider the umask value when setting the permissions of files, which might allow attackers to bypass intended access restrictions via standard filesystem operations. | Assigned (20110203) | None (candidate not yet proposed) | View | |
42745 | CVE-2010-0161 | Candidate | The nsAuthSSPI::Unwrap function in extensions/auth/nsAuthSSPI.cpp in Mozilla Thunderbird before 2.0.0.24 and SeaMonkey before 1.1.19 on Windows Vista, Windows Server 2008 R2, and Windows 7 allows remote SMTP, IMAP, and POP servers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via crafted data in a session that uses SSPI. | Assigned (20100106) | None (candidate not yet proposed) | View | |
43001 | CVE-2010-0417 | Candidate | Buffer overflow in common/util/rlstate.cpp in Helix Player 1.0.6 and RealPlayer allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a RuleBook structure with a large number of rule-separator characters that trigger heap memory corruption. | Assigned (20100127) | None (candidate not yet proposed) | View | |
43257 | CVE-2010-0673 | Candidate | SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress allows remote attackers to execute arbitrary SQL commands via the postid parameter. | Assigned (20100222) | None (candidate not yet proposed) | View | |
43513 | CVE-2010-0929 | Candidate | The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (daemon crash) via crafted data beginning with a byte sequence of 0x4c, 0xb3, 0xff, 0xff, and 0xff. | Assigned (20100305) | None (candidate not yet proposed) | View |
Page 20445 of 20943, showing 5 records out of 104715 total, starting on record 102221, ending on 102225