CVE List

Id CVE No. Status Description Phase Votes Comments Actions
43008  CVE-2010-0424  Candidate  The edit_cmd function in crontab.c in (1) cronie before 1.4.4 and (2) Vixie cron (vixie-cron) allows local users to change the modification times of arbitrary files, and consequently cause a denial of service, via a symlink attack on a temporary file in the /tmp directory.  Assigned (20100127)  None (candidate not yet proposed)    View
43264  CVE-2010-0680  Candidate  Directory traversal vulnerability in index.php in ZeusCMS 0.2 allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the page parameter.  Assigned (20100222)  None (candidate not yet proposed)    View
43520  CVE-2010-0936  Candidate  Cross-site scripting (XSS) vulnerability in auth.asp on the D-LINK DKVM-IP8 with firmware 2282_dlinkA4_p8_20071213 allows remote attackers to inject arbitrary web script or HTML via the nickname parameter.  Assigned (20100308)  None (candidate not yet proposed)    View
43776  CVE-2010-1192  Candidate  libESMTP, probably 1.0.4 and earlier, does not properly handle a "" character in a domain name in the subject"s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.  Assigned (20100330)  None (candidate not yet proposed)    View
44032  CVE-2010-1448  Candidate  Cross-site scripting (XSS) vulnerability in lib/LXR/Common.pm in LXR Cross Referencer before 0.9.8 allows remote attackers to inject arbitrary web script or HTML via vectors related to a string in the search page"s TITLE element, a different vulnerability than CVE-2009-4497 and CVE-2010-1625.  Assigned (20100415)  None (candidate not yet proposed)    View

Page 64 of 20943, showing 5 records out of 104715 total, starting on record 316, ending on 320

Actions