CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40207 | CVE-2009-2772 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in PG Roommate Finder Solution allow remote attackers to inject arbitrary web script or HTML via the part parameter to (1) quick_search.php and (2) viewprofile.php. | Assigned (20090814) | None (candidate not yet proposed) | View | |
40463 | CVE-2009-3028 | Candidate | The Altiris eXpress NS SC Download ActiveX control in AeXNSPkgDLLib.dll, as used in Symantec Altiris Deployment Solution 6.9.x, Notification Server 6.0.x, and Symantec Management Platform 7.0.x exposes an unsafe method, which allows remote attackers to force the download of arbitrary files and possibly execute arbitrary code via the DownloadAndInstall method. | Assigned (20090831) | None (candidate not yet proposed) | View | |
40719 | CVE-2009-3284 | Candidate | Directory traversal vulnerability in phpspot PHP BBS, PHP Image Capture BBS, PHP & CSS BBS, PHP BBS CE, PHP_RSS_Builder, and webshot, dated before 20090914, allows remote attackers to read arbitrary files via unspecified vectors. | Assigned (20090921) | None (candidate not yet proposed) | View | |
40975 | CVE-2009-3540 | Candidate | Cross-site scripting (XSS) vulnerability in listads.php in YourFreeWorld Ultra Classifieds Pro allows remote attackers to inject arbitrary web script or HTML via the cn parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | Assigned (20091002) | None (candidate not yet proposed) | View | |
41231 | CVE-2009-3796 | Candidate | Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors, related to a "data injection vulnerability." | Assigned (20091026) | None (candidate not yet proposed) | View |
Page 1270 of 20943, showing 5 records out of 104715 total, starting on record 6346, ending on 6350