CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47354  CVE-2010-4770  Candidate  SQL injection vulnerability in index.php in CommodityRentals DVD Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action.  Assigned (20110323)  None (candidate not yet proposed)    View
47610  CVE-2010-5026  Candidate  SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. NOTE: some of these details are obtained from third party information.  Assigned (20111102)  None (candidate not yet proposed)    View
47866  CVE-2010-5282  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in OpenText ECM (formerly Livelink ECM) 9.7.1 allow remote attackers to inject arbitrary web script or HTML via the (1) viewType and (2) sort parameters in a browse action to livelink/livelink; and the (3) nodeid, (4) setctx, and (5) support parameters to livelinkdav/nodes/OOB_DAVWindow.html.  Assigned (20121126)  None (candidate not yet proposed)    View
48122  CVE-2011-0210  Candidate  QuickTime in Apple Mac OS X before 10.6.8 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via crafted sample tables in a movie file.  Assigned (20101223)  None (candidate not yet proposed)    View
48378  CVE-2011-0466  Candidate  The API in SUSE openSUSE Build Service (OBS) 2.0.x before 2.0.8 and 2.1.x before 2.1.6 allows attackers to bypass intended write-access restrictions and modify a (1) package or (2) project via unspecified vectors.  Assigned (20110114)  None (candidate not yet proposed)    View

Page 20508 of 20943, showing 5 records out of 104715 total, starting on record 102536, ending on 102540

Actions