CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
39183 | CVE-2009-1748 | Candidate | Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) webpages_form or (2) userman_form parameter. | Assigned (20090521) | None (candidate not yet proposed) | View | |
39439 | CVE-2009-2004 | Candidate | Multiple SQL injection vulnerabilities in main/mySpace/myStudents.php in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) student and (2) course parameters, a different vector than CVE-2007-2902. | Assigned (20090608) | None (candidate not yet proposed) | View | |
39695 | CVE-2009-2260 | Candidate | stardict 3.0.1, when Enable Net Dict is configured, sends the contents of the clipboard to a dictionary server, which allows remote attackers to obtain sensitive information by sniffing the network. | Assigned (20090629) | None (candidate not yet proposed) | View | |
39951 | CVE-2009-2516 | Candidate | The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows Kernel NULL Pointer Dereference Vulnerability." | Assigned (20090717) | None (candidate not yet proposed) | View | |
40207 | CVE-2009-2772 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate Finder Solution allow remote attackers to inject arbitrary web script or HTML via the part parameter to (1) quick_search.php and (2) viewprofile.php. | Assigned (20090814) | None (candidate not yet proposed) | View |
Page 1254 of 20943, showing 5 records out of 104715 total, starting on record 6266, ending on 6270