CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40209  CVE-2009-2774  Candidate  SQL injection vulnerability in paidbanner.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitrary SQL commands via the ID parameter.  Assigned (20090814)  None (candidate not yet proposed)    View
40465  CVE-2009-3030  Candidate  Cross-site scripting (XSS) vulnerability in Symantec SecurityExpressions Audit and Compliance Server 4.1.1, 4.1, and earlier allows remote attackers to inject arbitrary web script or HTML via vectors that trigger an error message in a response, related to an "HTML Injection issue."  Assigned (20090831)  None (candidate not yet proposed)    View
40721  CVE-2009-3286  Candidate  NFSv4 in the Linux kernel 2.6.18, and possibly other versions, does not properly clean up an inode when an O_EXCL create fails, which causes files to be created with insecure settings such as setuid bits, and possibly allows local users to gain privileges, related to the execution of the do_open_permission function even when a create fails.  Assigned (20090922)  None (candidate not yet proposed)    View
40977  CVE-2009-3542  Candidate  Directory traversal vulnerability in ls.php in LittleSite (aka LS or LittleSite.php) 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the file parameter to index.php. NOTE: in some environments, this can be leveraged for remote file inclusion by using a UNC share pathname or an ftp, ftps, or ssh2.sftp URL.  Assigned (20091002)  None (candidate not yet proposed)    View
41233  CVE-2009-3798  Candidate  Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 might allow attackers to execute arbitrary code via unspecified vectors that trigger memory corruption.  Assigned (20091026)  None (candidate not yet proposed)    View

Page 1413 of 20943, showing 5 records out of 104715 total, starting on record 7061, ending on 7065

Actions