CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
43523 | CVE-2010-0939 | Candidate | Visialis ABB Forum 1.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for fpdb/abb.mdb. | Assigned (20100308) | None (candidate not yet proposed) | View | |
43779 | CVE-2010-1195 | Candidate | Cross-site scripting (XSS) vulnerability in the htmlscrubber component in ikiwiki 2.x before 2.53.5 and 3.x before 3.20100312 allows remote attackers to inject arbitrary web script or HTML via a crafted data:image/svg+xml URI. | Assigned (20100330) | None (candidate not yet proposed) | View | |
44035 | CVE-2010-1451 | Candidate | The TSB I-TLB load implementation in arch/sparc/kernel/tsb.S in the Linux kernel before 2.6.33 on the SPARC platform does not properly obtain the value of a certain _PAGE_EXEC_4U bit and consequently does not properly implement a non-executable stack, which makes it easier for context-dependent attackers to exploit stack-based buffer overflows via a crafted application. | Assigned (20100415) | None (candidate not yet proposed) | View | |
44291 | CVE-2010-1707 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in register.php in Piwigo 2.0.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) login and (2) mail_address parameters. | Assigned (20100504) | None (candidate not yet proposed) | View | |
44547 | CVE-2010-1963 | Candidate | Cross-site scripting (XSS) vulnerability in HP ServiceCenter allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20100519) | None (candidate not yet proposed) | View |
Page 307 of 20943, showing 5 records out of 104715 total, starting on record 1531, ending on 1535