CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41733  CVE-2009-4298  Candidate  The LAMS module (mod/lams) for Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 stores the (1) username, (2) firstname, and (3) lastname fields within the user table, which allows attackers to obtain user account information via unknown vectors.  Assigned (20091211)  None (candidate not yet proposed)    View
41989  CVE-2009-4554  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Snitz Forums 2000 3.4.07 allow remote attackers to inject arbitrary web script or HTML via (1) the url parameter to pop_send_to_friend.asp, related to a crafted onload attribute of an IMG element; or (2) an onload attribute in a sound tag.  Assigned (20100104)  None (candidate not yet proposed)    View
42245  CVE-2009-4810  Candidate  The Secure Remote Password (SRP) implementation in Samhain before 2.5.4 does not check for a certain zero value where required by the protocol, which allows remote attackers to bypass authentication via crafted input.  Assigned (20100423)  None (candidate not yet proposed)    View
42501  CVE-2009-5066  Candidate  twiddle.sh in JBoss AS 5.0 and EAP 5.0 and earlier accepts credentials as command-line arguments, which allows local users to read the credentials by listing the process and its arguments.  Assigned (20110405)  None (candidate not yet proposed)    View
42757  CVE-2010-0173  Candidate  Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.9 and 3.6.x before 3.6.2, Thunderbird before 3.0.4, and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.  Assigned (20100106)  None (candidate not yet proposed)    View

Page 1072 of 20943, showing 5 records out of 104715 total, starting on record 5356, ending on 5360

Actions