CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39180  CVE-2009-1745  Candidate  Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, has a default root password hash, and permits password-based root logins over SSH, which makes it easier for remote attackers to obtain access.  Assigned (20090521)  None (candidate not yet proposed)    View
39436  CVE-2009-2001  Candidate  Unspecified vulnerability in the PL/SQL component in Oracle Database 10.2.0.4 and 11.1.0.7 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.  Assigned (20090608)  None (candidate not yet proposed)    View
39692  CVE-2009-2257  Candidate  The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to (1) gateway/commands/saveconfig.html, and (2) stattbl.htm, (3) modemmenu.htm, (4) onload.htm, (5) form.css, (6) utility.js, and possibly (7) indextop.htm in html/.  Assigned (20090629)  None (candidate not yet proposed)    View
39948  CVE-2009-2513  Candidate  The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient Data Validation Vulnerability."  Assigned (20090717)  None (candidate not yet proposed)    View
40204  CVE-2009-2769  Candidate  PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter.  Assigned (20090814)  None (candidate not yet proposed)    View

Page 1016 of 20943, showing 5 records out of 104715 total, starting on record 5076, ending on 5080

Actions