CVE List

Id CVE No. Status Description Phase Votes Comments Actions
43005  CVE-2010-0421  Candidate  Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font"s charmap and the Unicode property database.  Assigned (20100127)  None (candidate not yet proposed)    View
43261  CVE-2010-0677  Candidate  SQL injection vulnerability in index.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the get parameter.  Assigned (20100222)  None (candidate not yet proposed)    View
43517  CVE-2010-0933  Candidate  Directory traversal vulnerability in Perforce Server 2008.1 allows remote authenticated users to create arbitrary files via a .. (dot dot) in the argument to the "p4 add" command.  Assigned (20100305)  None (candidate not yet proposed)    View
43773  CVE-2010-1189  Candidate  MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue."  Assigned (20100330)  None (candidate not yet proposed)    View
44029  CVE-2010-1445  Candidate  Heap-based buffer overflow in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted byte stream in an RTMP session.  Assigned (20100415)  None (candidate not yet proposed)    View

Page 20767 of 20943, showing 5 records out of 104715 total, starting on record 103831, ending on 103835

Actions