CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
41733 | CVE-2009-4298 | Candidate | The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within the user table, which allows attackers to obtain user account information via unknown vectors. | Assigned (20091211) | None (candidate not yet proposed) | View | |
41989 | CVE-2009-4554 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter to pop_send_to_friend.asp, related to a crafted onload attribute of an IMG element; or (2) an onload attribute in a sound tag. | Assigned (20100104) | None (candidate not yet proposed) | View | |
42245 | CVE-2009-4810 | Candidate | The Secure Remote Password (SRP) implementation in Samhain before 2.5.4 does not check for a certain zero value where required by the protocol, which allows remote attackers to bypass authentication via crafted input. | Assigned (20100423) | None (candidate not yet proposed) | View | |
42501 | CVE-2009-5066 | Candidate | twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments. | Assigned (20110405) | None (candidate not yet proposed) | View | |
42757 | CVE-2010-0173 | Candidate | Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors. | Assigned (20100106) | None (candidate not yet proposed) | View |
Page 1072 of 20943, showing 5 records out of 104715 total, starting on record 5356, ending on 5360