CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40975  CVE-2009-3540  Candidate  Cross-site scripting (XSS) vulnerability in listads.php in YourFreeWorld Ultra Classifieds Pro allows remote attackers to inject arbitrary web script or HTML via the cn parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20091002)  None (candidate not yet proposed)    View
41231  CVE-2009-3796  Candidate  Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors, related to a "data injection vulnerability."  Assigned (20091026)  None (candidate not yet proposed)    View
41487  CVE-2009-4052  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in the JSF Widget Library Runtime in IBM Rational Application Developer for WebSphere Software before 7.0.0.10 and Rational Software Architect before 7.0.0.10 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) the JSF Tree Control and (2) the JavaScript Resource Servlet.  Assigned (20091123)  None (candidate not yet proposed)    View
41743  CVE-2009-4308  Candidate  The ext4_decode_error function in fs/ext4/super.c in the ext4 filesystem in the Linux kernel before 2.6.32 allows user-assisted remote attackers to cause a denial of service (NULL pointer dereference), and possibly have unspecified other impact, via a crafted read-only filesystem that lacks a journal.  Assigned (20091212)  None (candidate not yet proposed)    View
41999  CVE-2009-4564  Candidate  SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote attackers to execute arbitrary SQL commands via the category parameter, related to a URI under news/category/.  Assigned (20100104)  None (candidate not yet proposed)    View

Page 1251 of 20943, showing 5 records out of 104715 total, starting on record 6251, ending on 6255

Actions