40976 |
CVE-2009-3541 |
Candidate |
PHP remote file inclusion vulnerability in CoupleDB.php in PHPGenealogy 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the DataDirectory parameter. |
Assigned (20091002) |
None (candidate not yet proposed) |
|
View
|
41232 |
CVE-2009-3797 |
Candidate |
Adobe Flash Player 10.x before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption. |
Assigned (20091026) |
None (candidate not yet proposed) |
|
View
|
41488 |
CVE-2009-4053 |
Candidate |
Multiple directory traversal vulnerabilities in Home FTP Server 1.10.1.139 allow remote authenticated users to (1) create arbitrary directories via directory traversal sequences in an MKD command or (2) create files with any contents in arbitrary directories via directory traversal sequences in a file upload request. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. |
Assigned (20091123) |
None (candidate not yet proposed) |
|
View
|
41744 |
CVE-2009-4309 |
Candidate |
Heap-based buffer overflow in the Intel Indeo41 codec for Windows Media Player in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to execute arbitrary code via a large size value in a movi record in an IV41 stream in a media file, as demonstrated by an AVI file. |
Assigned (20091212) |
None (candidate not yet proposed) |
|
View
|
42000 |
CVE-2009-4565 |
Candidate |
sendmail before 8.14.4 does not properly handle a " |