CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
39181 | CVE-2009-1746 | Candidate | SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary SQL commands via the id parameter in a detail action. | Assigned (20090521) | None (candidate not yet proposed) | View | |
39437 | CVE-2009-2002 | Candidate | Unspecified vulnerability in the WebLogic Portal component in BEA Product Suite 8.1.6, 9.2.3, 10.0.1, 10.2.1, and 10.3.1.0.0 allows remote attackers to affect integrity via unknown vectors. | Assigned (20090608) | None (candidate not yet proposed) | View | |
39693 | CVE-2009-2258 | Candidate | Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to list arbitrary directories via a .. (dot dot) in the nextpage parameter. | Assigned (20090629) | None (candidate not yet proposed) | View | |
39949 | CVE-2009-2514 | Candidate | win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded OpenType (EOT) font, aka "Win32k EOT Parsing Vulnerability." | Assigned (20090717) | None (candidate not yet proposed) | View | |
40205 | CVE-2009-2770 | Candidate | PowerUpload 2.4 allows remote attackers to bypass authentication and gain administrative access via a MIME encoded value of admin for the myadminname cookie. | Assigned (20090814) | None (candidate not yet proposed) | View |
Page 1096 of 20943, showing 5 records out of 104715 total, starting on record 5476, ending on 5480