CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
47354 | CVE-2010-4770 | Candidate | SQL injection vulnerability in index.php in CommodityRentals DVD Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action. | Assigned (20110323) | None (candidate not yet proposed) | View | |
47610 | CVE-2010-5026 | Candidate | SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. NOTE: some of these details are obtained from third party information. | Assigned (20111102) | None (candidate not yet proposed) | View | |
47866 | CVE-2010-5282 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in OpenText ECM (formerly Livelink ECM) 9.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewType and (2) sort parameters in a browse action to livelink/livelink; and the (3) nodeid, (4) setctx, and (5) support parameters to livelinkdav/nodes/OOB_DAVWindow.html. | Assigned (20121126) | None (candidate not yet proposed) | View | |
48122 | CVE-2011-0210 | Candidate | QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted sample tables in a movie file. | Assigned (20101223) | None (candidate not yet proposed) | View | |
48378 | CVE-2011-0466 | Candidate | The API in SUSE openSUSE Build Service (OBS) 2.0.x before 2.0.8 and 2.1.x before 2.1.6 allows attackers to bypass intended write-access restrictions and modify a (1) package or (2) project via unspecified vectors. | Assigned (20110114) | None (candidate not yet proposed) | View |
Page 20508 of 20943, showing 5 records out of 104715 total, starting on record 102536, ending on 102540