CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46585  CVE-2010-4001  Candidate  ** DISPUTED ** GMXRC.bash in Gromacs 4.5.1 and earlier places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: CVE disputes this issue because the GMXLDLIB value is always added to the beginning of LD_LIBRARY_PATH at a later point in the script.  Assigned (20101019)  None (candidate not yet proposed)    View
46841  CVE-2010-4257  Candidate  SQL injection vulnerability in the do_trackbacks function in wp-includes/comment.php in WordPress before 3.0.2 allows remote authenticated users to execute arbitrary SQL commands via the Send Trackbacks field.  Assigned (20101116)  None (candidate not yet proposed)    View
47097  CVE-2010-4513  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Zimplit CMS 3.0, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) file parameter in a load action to zimplit.php and (2) client parameter to English_manual_version_2.php.  Assigned (20101209)  None (candidate not yet proposed)    View
47353  CVE-2010-4769  Candidate  Directory traversal vulnerability in the Jimtawl (com_jimtawl) component 1.0.2 Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the task parameter to index.php.  Assigned (20110323)  None (candidate not yet proposed)    View
47609  CVE-2010-5025  Candidate  Cross-site scripting (XSS) vulnerability in manage/main.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote attackers to inject arbitrary web script or HTML via the fld_path parameter. NOTE: some of these details are obtained from third party information.  Assigned (20111102)  None (candidate not yet proposed)    View

Page 20451 of 20943, showing 5 records out of 104715 total, starting on record 102251, ending on 102255

Actions