CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40461 | CVE-2009-3026 | Candidate | protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions. | Assigned (20090831) | None (candidate not yet proposed) | View | |
40717 | CVE-2009-3282 | Candidate | Integer overflow in the vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 allows host OS users to cause a denial of service to the host OS via unspecified vectors. | Assigned (20090921) | None (candidate not yet proposed) | View | |
40973 | CVE-2009-3538 | Candidate | Directory traversal vulnerability in thumb.php in Clear Content 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | Assigned (20091002) | None (candidate not yet proposed) | View | |
41229 | CVE-2009-3794 | Candidate | Heap-based buffer overflow in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via crafted dimensions of JPEG data in an SWF file. | Assigned (20091026) | None (candidate not yet proposed) | View | |
41485 | CVE-2009-4050 | Candidate | Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 allows remote attackers to read arbitrary files via directory traversal sequences in the view parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | Assigned (20091123) | None (candidate not yet proposed) | View |
Page 1097 of 20943, showing 5 records out of 104715 total, starting on record 5481, ending on 5485