CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47612  CVE-2010-5028  Candidate  SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the catid parameter in an item action to index.php.  Assigned (20111102)  None (candidate not yet proposed)    View
47868  CVE-2010-5284  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Collabtive 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) User parameter in the edit user profile feature to manageuser.php, (2) y parameter in a newcal action to manageajax.php, and the (3) pic parameter to thumb.php.  Assigned (20121126)  None (candidate not yet proposed)    View
48124  CVE-2011-0212  Candidate  servermgrd in Apple Mac OS X before 10.6.8 allows remote attackers to read arbitrary files, and possibly send HTTP requests to intranet servers or cause a denial of service (CPU and memory consumption), via an XML-RPC request containing an entity declaration in conjunction with an entity reference, related to an XML External Entity (aka XXE) issue.  Assigned (20101223)  None (candidate not yet proposed)    View
48380  CVE-2011-0468  Candidate  The aaa_base package before 11.3-8.9.1 in SUSE openSUSE 11.3, and before 11.4-54.62.1 in openSUSE 11.4, allows local users to gain privileges via shell metacharacters in a filename, related to tab expansion.  Assigned (20110114)  None (candidate not yet proposed)    View
48636  CVE-2011-0724  Candidate  The Live DVD for Edubuntu 9.10, 10.04 LTS, and 10.10 does not correctly regenerate iTALC private keys after installation, which causes each installation to have the same fixed key, which allows remote attackers to gain privileges.  Assigned (20110201)  None (candidate not yet proposed)    View

Page 20662 of 20943, showing 5 records out of 104715 total, starting on record 103306, ending on 103310

Actions