CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46586  CVE-2010-4002  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20101019)  None (candidate not yet proposed)    View
46842  CVE-2010-4258  Candidate  The do_exit function in kernel/exit.c in the Linux kernel before 2.6.36.2 does not properly handle a KERNEL_DS get_fs value, which allows local users to bypass intended access_ok restrictions, overwrite arbitrary kernel memory locations, and gain privileges by leveraging a (1) BUG, (2) NULL pointer dereference, or (3) page fault, as demonstrated by vectors involving the clear_child_tid feature and the splice system call.  Assigned (20101116)  None (candidate not yet proposed)    View
47098  CVE-2010-4514  Candidate  Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter. NOTE: some of these details are obtained from third party information.  Assigned (20101209)  None (candidate not yet proposed)    View
47354  CVE-2010-4770  Candidate  SQL injection vulnerability in index.php in CommodityRentals DVD Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a catalog action.  Assigned (20110323)  None (candidate not yet proposed)    View
47610  CVE-2010-5026  Candidate  SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to execute arbitrary SQL commands via the type parameter. NOTE: some of these details are obtained from third party information.  Assigned (20111102)  None (candidate not yet proposed)    View

Page 20528 of 20943, showing 5 records out of 104715 total, starting on record 102636, ending on 102640

Actions