CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39949  CVE-2009-2514  Candidate  win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse font code during construction of a directory-entry table, which allows remote attackers to execute arbitrary code via a crafted Embedded OpenType (EOT) font, aka "Win32k EOT Parsing Vulnerability."  Assigned (20090717)  None (candidate not yet proposed)    View
40205  CVE-2009-2770  Candidate  PowerUpload 2.4 allows remote attackers to bypass authentication and gain administrative access via a MIME encoded value of admin for the myadminname cookie.  Assigned (20090814)  None (candidate not yet proposed)    View
40461  CVE-2009-3026  Candidate  protocols/jabber/auth.c in libpurple in Pidgin 2.6.0, and possibly other versions, does not follow the "require TLS/SSL" preference when connecting to older Jabber servers that do not follow the XMPP specification, which causes libpurple to connect to the server without the expected encryption and allows remote attackers to sniff sessions.  Assigned (20090831)  None (candidate not yet proposed)    View
40717  CVE-2009-3282  Candidate  Integer overflow in the vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 allows host OS users to cause a denial of service to the host OS via unspecified vectors.  Assigned (20090921)  None (candidate not yet proposed)    View
40973  CVE-2009-3538  Candidate  Directory traversal vulnerability in thumb.php in Clear Content 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the url parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20091002)  None (candidate not yet proposed)    View

Page 1109 of 20943, showing 5 records out of 104715 total, starting on record 5541, ending on 5545

Actions