CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
41223 | CVE-2009-3788 | Candidate | SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmuser (aka Username) parameter. | Assigned (20091026) | None (candidate not yet proposed) | View | |
41479 | CVE-2009-4044 | Candidate | The Web Services module 6.x for Drupal does not perform the expected access control, which allows remote attackers to make unspecified use of an API via unknown vectors. | Assigned (20091120) | None (candidate not yet proposed) | View | |
41735 | CVE-2009-4300 | Candidate | Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, even when the cached hashes are not used by the plugin, which might make it easier for attackers to obtain credentials via unspecified vectors. | Assigned (20091211) | None (candidate not yet proposed) | View | |
41991 | CVE-2009-4556 | Candidate | Quick Heal AntiVirus Plus 2009 10.00 SP1 and Quick Heal Total Security 2009 10.00 SP1 use weak permissions (Everyone: Full Control) for the product files, which allows local users to gain privileges by replacing executables with Trojan horse programs, as demonstrated by replacing quhlpsvc.exe. | Assigned (20100104) | None (candidate not yet proposed) | View | |
42247 | CVE-2009-4812 | Candidate | Wolfram Research webMathematica allows remote attackers to obtain sensitive information via a direct request to the MSP script, which reveals the installation path in an error message. | Assigned (20100427) | None (candidate not yet proposed) | View |
Page 1232 of 20943, showing 5 records out of 104715 total, starting on record 6156, ending on 6160