CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
43005 | CVE-2010-0421 | Candidate | Array index error in the hb_ot_layout_build_glyph_classes function in pango/opentype/hb-ot-layout.cc in Pango before 1.27.1 allows context-dependent attackers to cause a denial of service (application crash) via a crafted font file, related to building a synthetic Glyph Definition (aka GDEF) table by using this font"s charmap and the Unicode property database. | Assigned (20100127) | None (candidate not yet proposed) | View | |
43261 | CVE-2010-0677 | Candidate | SQL injection vulnerability in index.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, allows remote attackers to execute arbitrary SQL commands via the get parameter. | Assigned (20100222) | None (candidate not yet proposed) | View | |
43517 | CVE-2010-0933 | Candidate | Directory traversal vulnerability in Perforce Server 2008.1 allows remote authenticated users to create arbitrary files via a .. (dot dot) in the argument to the "p4 add" command. | Assigned (20100305) | None (candidate not yet proposed) | View | |
43773 | CVE-2010-1189 | Candidate | MediaWiki before 1.15.2 does not prevent wiki editors from linking to images from other web sites in wiki pages, which allows editors to obtain IP addresses and other information of wiki users by adding a link to an image on an attacker-controlled web site, aka "CSS validation issue." | Assigned (20100330) | None (candidate not yet proposed) | View | |
44029 | CVE-2010-1445 | Candidate | Heap-based buffer overflow in VideoLAN VLC media player before 1.0.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted byte stream in an RTMP session. | Assigned (20100415) | None (candidate not yet proposed) | View |
Page 20767 of 20943, showing 5 records out of 104715 total, starting on record 103831, ending on 103835