CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47609  CVE-2010-5025  Candidate  Cross-site scripting (XSS) vulnerability in manage/main.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote attackers to inject arbitrary web script or HTML via the fld_path parameter. NOTE: some of these details are obtained from third party information.  Assigned (20111102)  None (candidate not yet proposed)    View
47865  CVE-2010-5281  Candidate  Directory traversal vulnerability in ibrowser.php in the CMScout 2.09 IBrowser TinyMCE Plugin 1.4.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter. NOTE: some of these details are obtained from third party information.  Assigned (20121126)  None (candidate not yet proposed)    View
48121  CVE-2011-0209  Candidate  Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RIFF WAV file.  Assigned (20101223)  None (candidate not yet proposed)    View
48377  CVE-2011-0465  Candidate  xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2) XDMCP message.  Assigned (20110114)  None (candidate not yet proposed)    View
48633  CVE-2011-0721  Candidate  Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field.  Assigned (20110201)  None (candidate not yet proposed)    View

Page 20449 of 20943, showing 5 records out of 104715 total, starting on record 102241, ending on 102245

Actions