CVE List

Id CVE No. Status Description Phase Votes Comments Actions
46333  CVE-2010-3749  Candidate  The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows remote attackers to arguments to the RecordClip method, which allows remote attackers to download an arbitrary program onto a client machine, and execute this program, via a " (double quote) in an argument to the RecordClip method, aka "parameter injection."  Assigned (20101005)  None (candidate not yet proposed)    View
46589  CVE-2010-4005  Candidate  The (1) tomboy and (2) tomboy-panel scripts in GNOME Tomboy 1.5.2 and earlier place a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. NOTE: vector 1 exists because of an incorrect fix for CVE-2005-4790.2.  Assigned (20101019)  None (candidate not yet proposed)    View
46845  CVE-2010-4261  Candidate  Off-by-one error in the icon_cb function in pe_icons.c in libclamav in ClamAV before 0.96.5 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unspecified vectors. NOTE: some of these details are obtained from third party information.  Assigned (20101116)  None (candidate not yet proposed)    View
47101  CVE-2010-4517  Candidate  SQL injection vulnerability in the JExtensions JE Auto (com_jeauto) component 1.0 for Joomla!, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the char parameter in an item action to index.php.  Assigned (20101209)  None (candidate not yet proposed)    View
47357  CVE-2010-4773  Candidate  Unspecified vulnerability in Hitachi EUR Form Client before 05-10 -/D 2010.11.15 and 05-10-CA (* 2) 2010.11.15; Hitachi EUR Form Service before 05-10 -/D 2010.11.15; and uCosminexus EUR Form Service before 07-60 -/D 2010.11.15 on Windows, before 05-10 -/D 2010.11.15 and 07-50 -/D 2010.11.15 on Linux, and before 07-50 -/C 2010.11.15 on AIX; allows remote attackers to execute arbitrary code via unknown attack vectors.  Assigned (20110323)  None (candidate not yet proposed)    View

Page 20768 of 20943, showing 5 records out of 104715 total, starting on record 103836, ending on 103840

Actions