CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41223  CVE-2009-3788  Candidate  SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmuser (aka Username) parameter.  Assigned (20091026)  None (candidate not yet proposed)    View
41479  CVE-2009-4044  Candidate  The Web Services module 6.x for Drupal does not perform the expected access control, which allows remote attackers to make unspecified use of an API via unknown vectors.  Assigned (20091120)  None (candidate not yet proposed)    View
41735  CVE-2009-4300  Candidate  Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, even when the cached hashes are not used by the plugin, which might make it easier for attackers to obtain credentials via unspecified vectors.  Assigned (20091211)  None (candidate not yet proposed)    View
41991  CVE-2009-4556  Candidate  Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs, as demonstrated by replacing quhlpsvc.exe.  Assigned (20100104)  None (candidate not yet proposed)    View
42247  CVE-2009-4812  Candidate  Wolfram Research webMathematica allows remote attackers to obtain sensitive information via a direct request to the MSP script, which reveals the installation path in an error message.  Assigned (20100427)  None (candidate not yet proposed)    View

Page 1232 of 20943, showing 5 records out of 104715 total, starting on record 6156, ending on 6160

Actions