CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
47609 | CVE-2010-5025 | Candidate | Cross-site scripting (XSS) vulnerability in manage/main.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote attackers to inject arbitrary web script or HTML via the fld_path parameter. NOTE: some of these details are obtained from third party information. | Assigned (20111102) | None (candidate not yet proposed) | View | |
47865 | CVE-2010-5281 | Candidate | Directory traversal vulnerability in ibrowser.php in the CMScout 2.09 IBrowser TinyMCE Plugin 1.4.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter. NOTE: some of these details are obtained from third party information. | Assigned (20121126) | None (candidate not yet proposed) | View | |
48121 | CVE-2011-0209 | Candidate | Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RIFF WAV file. | Assigned (20101223) | None (candidate not yet proposed) | View | |
48377 | CVE-2011-0465 | Candidate | xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2) XDMCP message. | Assigned (20110114) | None (candidate not yet proposed) | View | |
48633 | CVE-2011-0721 | Candidate | Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field. | Assigned (20110201) | None (candidate not yet proposed) | View |
Page 20449 of 20943, showing 5 records out of 104715 total, starting on record 102241, ending on 102245