CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
42251 | CVE-2009-4816 | Candidate | Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter. | Assigned (20100427) | None (candidate not yet proposed) | View | |
42507 | CVE-2009-5072 | Candidate | Memory leak in the ldap_explode_dn function in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.61 (aka 6.0.0.8-TIV-ITDS-IF0003) allows remote authenticated users to cause a denial of service (memory consumption) via an empty string argument. | Assigned (20110420) | None (candidate not yet proposed) | View | |
42763 | CVE-2010-0179 | Candidate | Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response. | Assigned (20100106) | None (candidate not yet proposed) | View | |
43019 | CVE-2010-0435 | Candidate | The Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2, and KVM 83, when the Intel VT-x extension is enabled, allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via vectors related to instruction emulation. | Assigned (20100127) | None (candidate not yet proposed) | View | |
43275 | CVE-2010-0691 | Candidate | SQL injection vulnerability in druckansicht.php in JTL-Shop 2 allows remote attackers to execute arbitrary SQL commands via the s parameter. | Assigned (20100223) | None (candidate not yet proposed) | View |
Page 945 of 20943, showing 5 records out of 104715 total, starting on record 4721, ending on 4725