CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47621  CVE-2010-5037  Candidate  SQL injection vulnerability in article.php in SenseSites CommonSense CMS allows remote attackers to execute arbitrary SQL commands via the article_id parameter.  Assigned (20111102)  None (candidate not yet proposed)    View
47877  CVE-2010-5293  Candidate  wp-includes/comment.php in WordPress before 3.0.2 does not properly whitelist trackbacks and pingbacks in the blogroll, which allows remote attackers to bypass intended spam restrictions via a crafted URL, as demonstrated by a URL that triggers a substring match.  Assigned (20140120)  None (candidate not yet proposed)    View
48133  CVE-2011-0221  Candidate  WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.  Assigned (20101223)  None (candidate not yet proposed)    View
48389  CVE-2011-0477  Candidate  Google Chrome before 8.0.552.237 and Chrome OS before 8.0.552.344 do not properly handle a mismatch in video frame sizes, which allows remote attackers to cause a denial of service (incorrect memory access) or possibly have unspecified other impact via unknown vectors.  Assigned (20110114)  None (candidate not yet proposed)    View
48645  CVE-2011-0733  Candidate  Cross-site scripting (XSS) vulnerability in Adobe ColdFusion before 9.0.1 CHF1 allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header in an id=- query to a .cfm file.  Assigned (20110201)  None (candidate not yet proposed)    View

Page 471 of 20943, showing 5 records out of 104715 total, starting on record 2351, ending on 2355

Actions