CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39689  CVE-2009-2254  Candidate  Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows remote attackers to execute arbitrary SQL commands via the query_string parameter in an execute action, in conjunction with a PATH_INFO of password_forgotten.php, related to a "SQL Execution" issue.  Assigned (20090629)  None (candidate not yet proposed)    View
39945  CVE-2009-2510  Candidate  The CryptoAPI component in Microsoft Windows 2000 SP4, Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7, as used by Internet Explorer and other applications, does not properly handle a "" character in a domain name in the subject"s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, aka "Null Truncation in X.509 Common Name Vulnerability," a related issue to CVE-2009-2408.  Assigned (20090717)  None (candidate not yet proposed)    View
40201  CVE-2009-2766  Candidate  httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remote attackers to change settings via HTTP requests.  Assigned (20090814)  None (candidate not yet proposed)    View
40457  CVE-2009-3022  Candidate  Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other users for requests that modify configuration or change content via unspecified vectors.  Assigned (20090831)  None (candidate not yet proposed)    View
40713  CVE-2009-3278  Candidate  The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery key, which makes it easier for local users to determine this key via a brute-force attack.  Assigned (20090921)  None (candidate not yet proposed)    View

Page 1390 of 20943, showing 5 records out of 104715 total, starting on record 6946, ending on 6950

Actions