CVE List

Id CVE No. Status Description Phase Votes Comments Actions
43258  CVE-2010-0674  Candidate  StatCounteX 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for path/stats.mdb.  Assigned (20100222)  None (candidate not yet proposed)    View
43514  CVE-2010-0930  Candidate  The Perforce service (p4s.exe) in Perforce Server 2008.1 allows remote attackers to cause a denial of service (infinite loop) via crafted data that includes a byte sequence of 0xdc, 0xff, 0xff, and 0xff immediately before the client protocol version number.  Assigned (20100305)  None (candidate not yet proposed)    View
43770  CVE-2010-1186  Candidate  Cross-site scripting (XSS) vulnerability in xml/media-rss.php in the NextGEN Gallery plugin before 1.5.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the mode parameter.  Assigned (20100330)  None (candidate not yet proposed)    View
44026  CVE-2010-1442  Candidate  VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (invalid memory access and application crash) or possibly execute arbitrary code via a crafted byte stream to the (1) AVI, (2) ASF, or (3) Matroska (aka MKV) demuxer.  Assigned (20100415)  None (candidate not yet proposed)    View
44282  CVE-2010-1698  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20100430)  None (candidate not yet proposed)    View

Page 20528 of 20943, showing 5 records out of 104715 total, starting on record 102636, ending on 102640

Actions