CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
43266 | CVE-2010-0682 | Candidate | WordPress 2.9 before 2.9.2 allows remote authenticated users to read trash posts from other authors via a direct request with a modified p parameter. | Assigned (20100222) | None (candidate not yet proposed) | View | |
43522 | CVE-2010-0938 | Candidate | Cross-site scripting (XSS) vulnerability in todooforum.php in Todoo Forum 2.0 allows remote attackers to inject arbitrary web script or HTML via the id_forum parameter in a post action. | Assigned (20100308) | None (candidate not yet proposed) | View | |
43778 | CVE-2010-1194 | Candidate | The match_component function in smtp-tls.c in libESMTP 1.0.3.r1, and possibly other versions including 1.0.4, treats two strings as equal if one is a substring of the other, which allows remote attackers to spoof trusted certificates via a crafted subjectAltName. | Assigned (20100330) | None (candidate not yet proposed) | View | |
44034 | CVE-2010-1450 | Candidate | Multiple buffer overflows in the RLE decoder in the rgbimg module in Python 2.5 allow remote attackers to have an unspecified impact via an image file containing crafted data that triggers improper processing within the (1) longimagedata or (2) expandrow function. | Assigned (20100415) | None (candidate not yet proposed) | View | |
44290 | CVE-2010-1706 | Candidate | Multiple SQL injection vulnerabilities in login.php in 2daybiz Auction Script allow remote attackers to execute arbitrary SQL commands via (1) the login field (aka the username parameter), and possibly (2) the password field, to index.php. NOTE: some of these details are obtained from third party information. | Assigned (20100504) | None (candidate not yet proposed) | View |
Page 226 of 20943, showing 5 records out of 104715 total, starting on record 1126, ending on 1130