CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
47865 | CVE-2010-5281 | Candidate | Directory traversal vulnerability in ibrowser.php in the CMScout 2.09 IBrowser TinyMCE Plugin 1.4.1, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter. NOTE: some of these details are obtained from third party information. | Assigned (20121126) | None (candidate not yet proposed) | View | |
48121 | CVE-2011-0209 | Candidate | Integer overflow in QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted RIFF WAV file. | Assigned (20101223) | None (candidate not yet proposed) | View | |
48377 | CVE-2011-0465 | Candidate | xrdb.c in xrdb before 1.0.9 in X.Org X11R7.6 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in a hostname obtained from a (1) DHCP or (2) XDMCP message. | Assigned (20110114) | None (candidate not yet proposed) | View | |
48633 | CVE-2011-0721 | Candidate | Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field. | Assigned (20110201) | None (candidate not yet proposed) | View | |
48889 | CVE-2011-0977 | Candidate | Use-after-free vulnerability in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac allows remote attackers to execute arbitrary code via malformed shape data in the Office drawing file format, aka "Microsoft Office Graphic Object Dereferencing Vulnerability." | Assigned (20110210) | None (candidate not yet proposed) | View |
Page 20452 of 20943, showing 5 records out of 104715 total, starting on record 102256, ending on 102260