CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39183  CVE-2009-1748  Candidate  Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) webpages_form or (2) userman_form parameter.  Assigned (20090521)  None (candidate not yet proposed)    View
39439  CVE-2009-2004  Candidate  Multiple SQL injection vulnerabilities in main/mySpace/myStudents.php in Dokeos 1.8.5, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) student and (2) course parameters, a different vector than CVE-2007-2902.  Assigned (20090608)  None (candidate not yet proposed)    View
39695  CVE-2009-2260  Candidate  stardict 3.0.1, when Enable Net Dict is configured, sends the contents of the clipboard to a dictionary server, which allows remote attackers to obtain sensitive information by sniffing the network.  Assigned (20090629)  None (candidate not yet proposed)    View
39951  CVE-2009-2516  Candidate  The kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold and SP1, and Server 2008 Gold does not properly validate data sent from user mode, which allows local users to gain privileges via a crafted PE .exe file that triggers a NULL pointer dereference during chain traversal, aka "Windows Kernel NULL Pointer Dereference Vulnerability."  Assigned (20090717)  None (candidate not yet proposed)    View
40207  CVE-2009-2772  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate Finder Solution allow remote attackers to inject arbitrary web script or HTML via the part parameter to (1) quick_search.php and (2) viewprofile.php.  Assigned (20090814)  None (candidate not yet proposed)    View

Page 1254 of 20943, showing 5 records out of 104715 total, starting on record 6266, ending on 6270

Actions