CVE List

Id CVE No. Status Description Phase Votes Comments Actions
38661  CVE-2009-1226  Candidate  core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.  Assigned (20090402)  None (candidate not yet proposed)    View
104197  CVE-2017-7377  Candidate  The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.  Assigned (20170331)  None (candidate not yet proposed)    View
38917  CVE-2009-1482  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an AttachFile sub-action in the error_msg function or (2) multiple vectors related to package file errors in the upload_form function, different vectors than CVE-2009-0260.  Assigned (20090429)  None (candidate not yet proposed)    View
104453  CVE-2017-7633  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170410)  None (candidate not yet proposed)    View
39173  CVE-2009-1738  Candidate  Cross-site scripting (XSS) vulnerability in Feed Block 6.x-1.x before 6.x-1.1, a module for Drupal, allows remote authenticated users with administrator feed permissions to inject arbitrary web script or HTML via unspecified vectors in "aggregator items."  Assigned (20090520)  None (candidate not yet proposed)    View

Page 1069 of 20943, showing 5 records out of 104715 total, starting on record 5341, ending on 5345

Actions