CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42241  CVE-2009-4806  Candidate  admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator"s credentials via unspecified vectors. NOTE: some of these details are obtained from third party information.  Assigned (20100423)  None (candidate not yet proposed)    View
42497  CVE-2009-5062  Candidate  IBM Lotus Quickr 8.1 before 8.1.0.15 services for Lotus Domino on AIX allows remote authenticated users to cause a denial of service (daemon crash) by subscribing to an Atom feed, aka SPR JRIE7VKMP9.  Assigned (20110322)  None (candidate not yet proposed)    View
42753  CVE-2010-0169  Candidate  The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the browser"s font and other CSS attributes, and potentially disrupt rendering of a web page, by forcing the browser to perform this erroneous stylesheet caching.  Assigned (20100106)  None (candidate not yet proposed)    View
43009  CVE-2010-0425  Candidate  modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers."  Assigned (20100127)  None (candidate not yet proposed)    View
43265  CVE-2010-0681  Candidate  ZeusCMS 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request for admin/backup.sql.  Assigned (20100222)  None (candidate not yet proposed)    View

Page 142 of 20943, showing 5 records out of 104715 total, starting on record 706, ending on 710

Actions