CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
46341 | CVE-2010-3757 | Candidate | Format string vulnerability in the _Eventlog function in FastBackServer.exe in the Server in IBM Tivoli Storage Manager (TSM) FastBack 5.5.0.0 through 5.5.6.0 and 6.1.0.0 through 6.1.0.1 allows remote attackers to execute arbitrary code via format string specifiers located after a | (pipe) character in a string. NOTE: this might overlap CVE-2010-3059. | Assigned (20101005) | None (candidate not yet proposed) | View | |
46597 | CVE-2010-4013 | Candidate | Format string vulnerability in PackageKit in Apple Mac OS X 10.6.x before 10.6.6 allows man-in-the-middle attackers to execute arbitrary code or cause a denial of service (application crash) via vectors related to interaction between Software Update and distribution scripts. | Assigned (20101020) | None (candidate not yet proposed) | View | |
46853 | CVE-2010-4269 | Candidate | SQL injection vulnerability in managechat.php in Collabtive 0.65 allows remote attackers to execute arbitrary SQL commands via the chatstart[USERTOID] cookie in a pull action. | Assigned (20101116) | None (candidate not yet proposed) | View | |
47109 | CVE-2010-4525 | Candidate | Linux kernel 2.6.33 and 2.6.34.y does not initialize the kvm_vcpu_events->interrupt.pad structure member, which allows local users to obtain potentially sensitive information from kernel stack memory via unspecified vectors. | Assigned (20101209) | None (candidate not yet proposed) | View | |
47365 | CVE-2010-4781 | Candidate | index.php in Enano CMS 1.1.7pl1, and possibly other versions before 1.1.8, 1.0.6pl3, and 1.1.7pl2, allows remote attackers to obtain sensitive information via a crafted title parameter, which reveals the installation path in an error message. | Assigned (20110407) | None (candidate not yet proposed) | View |
Page 465 of 20943, showing 5 records out of 104715 total, starting on record 2321, ending on 2325