CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47865  CVE-2010-5281  Candidate  Directory traversal vulnerability in ibrowser.php in the CMScout 2.09 IBrowser TinyMCE Plugin 1.4.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter. NOTE: some of these details are obtained from third party information.  Assigned (20121126)  None (candidate not yet proposed)    View
48121  CVE-2011-0209  Candidate  Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RIFF WAV file.  Assigned (20101223)  None (candidate not yet proposed)    View
48377  CVE-2011-0465  Candidate  xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2) XDMCP message.  Assigned (20110114)  None (candidate not yet proposed)    View
48633  CVE-2011-0721  Candidate  Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field.  Assigned (20110201)  None (candidate not yet proposed)    View
48889  CVE-2011-0977  Candidate  Use-after-free vulnerability in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via malformed shape data in the Office drawing file format, aka "Microsoft Office Graphic Object Dereferencing Vulnerability."  Assigned (20110210)  None (candidate not yet proposed)    View

Page 20452 of 20943, showing 5 records out of 104715 total, starting on record 102256, ending on 102260

Actions