CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39181  CVE-2009-1746  Candidate  SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action.  Assigned (20090521)  None (candidate not yet proposed)    View
39437  CVE-2009-2002  Candidate  Unspecified vulnerability in the WebLogic Portal component in BEA Product Suite 8.1.6, 9.2.3, 10.0.1, 10.2.1, and 10.3.1.0.0 allows remote attackers to affect integrity via unknown vectors.  Assigned (20090608)  None (candidate not yet proposed)    View
39693  CVE-2009-2258  Candidate  Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to list arbitrary directories via a .. (dot dot) in the nextpage parameter.  Assigned (20090629)  None (candidate not yet proposed)    View
39949  CVE-2009-2514  Candidate  win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded OpenType (EOT) font, aka "Win32k EOT Parsing Vulnerability."  Assigned (20090717)  None (candidate not yet proposed)    View
40205  CVE-2009-2770  Candidate  PowerUpload 2.4 allows remote attackers to bypass authentication and gain administrative access via a MIME encoded value of admin for the myadminname cookie.  Assigned (20090814)  None (candidate not yet proposed)    View

Page 1096 of 20943, showing 5 records out of 104715 total, starting on record 5476, ending on 5480

Actions