CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42492  CVE-2009-5057  Candidate  The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 does not configure the RANDFILE and HOME environment variables for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seeding file.  Assigned (20110318)  None (candidate not yet proposed)    View
42748  CVE-2010-0164  Candidate  Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace animation in which the frames have different bits-per-pixel (bpp) values.  Assigned (20100106)  None (candidate not yet proposed)    View
43004  CVE-2010-0420  Candidate  libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing <br> sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname.  Assigned (20100127)  None (candidate not yet proposed)    View
43260  CVE-2010-0676  Candidate  Directory traversal vulnerability in index.php in the RWCards (com_rwcards) component 3.0.18 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter.  Assigned (20100222)  None (candidate not yet proposed)    View
43516  CVE-2010-0932  Candidate  The FTP server in Perforce Server 2008.1 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a certain MKD command.  Assigned (20100305)  None (candidate not yet proposed)    View

Page 20658 of 20943, showing 5 records out of 104715 total, starting on record 103286, ending on 103290

Actions