CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39943  CVE-2009-2508  Candidate  The single sign-on implementation in Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly remove credentials at the end of a network session, which allows physically proximate attackers to obtain the credentials of a previous user of the same web browser by using data from the browser"s cache, aka "Single Sign On Spoofing in ADFS Vulnerability."  Assigned (20090717)  None (candidate not yet proposed)    View
40199  CVE-2009-2764  Candidate  Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of service (application crash) via a certain DIV element in conjunction with SCRIPT elements that have empty contents and no reference to a valid external script location.  Assigned (20090814)  None (candidate not yet proposed)    View
40455  CVE-2009-3020  Candidate  win32k.sys in Microsoft Windows Server 2003 SP2 allows remote attackers to cause a denial of service (system crash) by referencing a crafted .eot file in the src descriptor of an @font-face Cascading Style Sheets (CSS) rule in an HTML document, possibly related to the Embedded OpenType (EOT) Font Engine, a different vulnerability than CVE-2006-0010, CVE-2009-0231, and CVE-2009-0232. NOTE: some of these details are obtained from third party information.  Assigned (20090831)  None (candidate not yet proposed)    View
40711  CVE-2009-3276  Candidate  Zoran/WinFormsAdvansed/RegeularDataToXML/Form1.cs in WinFormsAdvansed in NASD CORE.NET Terelik (aka corenet1) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many alphabetic characters followed by a ! (exclamation point), related to a certain regular expression, aka a "ReDoS" vulnerability.  Assigned (20090921)  None (candidate not yet proposed)    View
40967  CVE-2009-3532  Candidate  Multiple SQL injection vulnerabilities in login.asp (aka the login screen) in LogRover 2.3 and 2.3.3 on Windows allow remote attackers to execute arbitrary SQL commands via the (1) uname and (2) pword parameters. NOTE: some of these details are obtained from third party information.  Assigned (20091002)  None (candidate not yet proposed)    View

Page 1231 of 20943, showing 5 records out of 104715 total, starting on record 6151, ending on 6155

Actions