CVE List

Id CVE No. Status Description Phase Votes Comments Actions
47113  CVE-2010-4529  Candidate  Integer underflow in the irda_getsockopt function in net/irda/af_irda.c in the Linux kernel before 2.6.37 on platforms other than x86 allows local users to obtain potentially sensitive information from kernel heap memory via an IRLMP_ENUMDEVICES getsockopt call.  Assigned (20101209)  None (candidate not yet proposed)    View
47369  CVE-2010-4785  Candidate  The do_extendedOp function in ibmslapd in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.62 (aka 6.0.0.8-TIV-ITDS-IF0004) on Linux, Solaris, and Windows allows remote authenticated users to cause a denial of service (ABEND) via a malformed LDAP extended operation that triggers certain comparisons involving the NULL operation OID.  Assigned (20110420)  None (candidate not yet proposed)    View
47625  CVE-2010-5041  Candidate  SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary SQL commands via the id parameter in a plugin action.  Assigned (20111102)  None (candidate not yet proposed)    View
47881  CVE-2010-5297  Candidate  WordPress before 3.0.1, when a Multisite installation is used, permanently retains the "site administrators can add users" option once changed, which might allow remote authenticated administrators to bypass intended access restrictions in opportunistic circumstances via an add action after a temporary change.  Assigned (20140120)  None (candidate not yet proposed)    View
48137  CVE-2011-0225  Candidate  WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2011-07-20-1.  Assigned (20101223)  None (candidate not yet proposed)    View

Page 795 of 20943, showing 5 records out of 104715 total, starting on record 3971, ending on 3975

Actions