CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42513  CVE-2009-5078  Candidate  contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 launches the Ghostscript program without the -dSAFER option, which allows remote attackers to create, overwrite, rename, or delete arbitrary files via a crafted document.  Assigned (20110630)  None (candidate not yet proposed)    View
42769  CVE-2010-0185  Candidate  The default configuration of Adobe ColdFusion 9.0 does not restrict access to collections that have been created by the Solr Service, which allows remote attackers to obtain collection metadata, search information, and index data via a request to an unspecified URL.  Assigned (20100106)  None (candidate not yet proposed)    View
43025  CVE-2010-0441  Candidate  Asterisk Open Source 1.6.0.x before 1.6.0.22, 1.6.1.x before 1.6.1.14, and 1.6.2.x before 1.6.2.2, and Business Edition C.3 before C.3.3.2, allows remote attackers to cause a denial of service (daemon crash) via an SIP T.38 negotiation with an SDP FaxMaxDatagram field that is (1) missing, (2) modified to contain a negative number, or (3) modified to contain a large number.  Assigned (20100127)  None (candidate not yet proposed)    View
43281  CVE-2010-0697  Candidate  Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inject arbitrary web script or HTML via the file name of an uploaded file.  Assigned (20100223)  None (candidate not yet proposed)    View
43537  CVE-2010-0953  Candidate  Directory traversal vulnerability in mod.php in phpCOIN 1.2.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the mod parameter.  Assigned (20100309)  None (candidate not yet proposed)    View

Page 1406 of 20943, showing 5 records out of 104715 total, starting on record 7026, ending on 7030

Actions