CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42251  CVE-2009-4816  Candidate  Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.  Assigned (20100427)  None (candidate not yet proposed)    View
42507  CVE-2009-5072  Candidate  Memory leak in the ldap_explode_dn function in IBM Tivoli Directory Server (TDS) 6.0 before 6.0.0.61 (aka 6.0.0.8-TIV-ITDS-IF0003) allows remote authenticated users to cause a denial of service (memory consumption) via an empty string argument.  Assigned (20110420)  None (candidate not yet proposed)    View
42763  CVE-2010-0179  Candidate  Mozilla Firefox before 3.0.19 and 3.5.x before 3.5.8, and SeaMonkey before 2.0.3, when the XMLHttpRequestSpy module in the Firebug add-on is used, does not properly handle interaction between the XMLHttpRequestSpy object and chrome privileged objects, which allows remote attackers to execute arbitrary JavaScript via a crafted HTTP response.  Assigned (20100106)  None (candidate not yet proposed)    View
43019  CVE-2010-0435  Candidate  The Hypervisor (aka rhev-hypervisor) in Red Hat Enterprise Virtualization (RHEV) 2.2, and KVM 83, when the Intel VT-x extension is enabled, allows guest OS users to cause a denial of service (NULL pointer dereference and host OS crash) via vectors related to instruction emulation.  Assigned (20100127)  None (candidate not yet proposed)    View
43275  CVE-2010-0691  Candidate  SQL injection vulnerability in druckansicht.php in JTL-Shop 2 allows remote attackers to execute arbitrary SQL commands via the s parameter.  Assigned (20100223)  None (candidate not yet proposed)    View

Page 945 of 20943, showing 5 records out of 104715 total, starting on record 4721, ending on 4725

Actions