CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42256  CVE-2009-4821  Candidate  The D-Link DIR-615 with firmware 3.10NA does not require administrative authentication for apply.cgi, which allows remote attackers to (1) change the admin password via the admin_password parameter, (2) disable the security requirement for the Wi-Fi network via unspecified vectors, or (3) modify DNS settings via unspecified vectors.  Assigned (20100427)  None (candidate not yet proposed)    View
42512  CVE-2009-5077  Candidate  CRE Loaded before 6.2.14 allows remote attackers to bypass authentication and gain administrator privileges via vectors related to a modified PHP_SELF variable, which is not properly handled by (1) includes/application_top.php and (2) admin/includes/application_top.php.  Assigned (20110608)  None (candidate not yet proposed)    View
42768  CVE-2010-0184  Candidate  The (1) domainutility and (2) domainutilitycmd components in TIBCO Domain Utility in TIBCO Runtime Agent (TRA) before 5.6.2, as used in TIBCO ActiveMatrix BusinessWorks and other products, set weak permissions on domain properties files, which allows local users to obtain domain administrator credentials, and gain privileges on all domain systems, via unspecified vectors.  Assigned (20100106)  None (candidate not yet proposed)    View
43024  CVE-2010-0440  Candidate  Cross-site scripting (XSS) vulnerability in +CSCOT+/translation in Cisco Secure Desktop 3.4.2048, and other versions before 3.5; as used in Cisco ASA appliance before 8.2(1), 8.1(2.7), and 8.0(5); allows remote attackers to inject arbitrary web script or HTML via a crafted POST parameter, which is not properly handled by an eval statement in binary/mainv.js that writes to start.html.  Assigned (20100127)  None (candidate not yet proposed)    View
43280  CVE-2010-0696  Candidate  Directory traversal vulnerability in includes/download.php in the JoomlaWorks AllVideos (Jw_allVideos) plugin 3.0 through 3.2 for Joomla! allows remote attackers to read arbitrary files via a ./../.../ (modified dot dot) in the file parameter.  Assigned (20100223)  None (candidate not yet proposed)    View

Page 1335 of 20943, showing 5 records out of 104715 total, starting on record 6671, ending on 6675

Actions