CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
42241 | CVE-2009-4806 | Candidate | admin/save_user.asp in Digital Interchange Document Library 1.0.1 does not require administrative authentication, which allows remote attackers to read or modify the administrator"s credentials via unspecified vectors. NOTE: some of these details are obtained from third party information. | Assigned (20100423) | None (candidate not yet proposed) | View | |
42497 | CVE-2009-5062 | Candidate | IBM Lotus Quickr 8.1 before 8.1.0.15 services for Lotus Domino on AIX allows remote authenticated users to cause a denial of service (daemon crash) by subscribing to an Atom feed, aka SPR JRIE7VKMP9. | Assigned (20110322) | None (candidate not yet proposed) | View | |
42753 | CVE-2010-0169 | Candidate | The CSSLoaderImpl::DoSheetComplete function in layout/style/nsCSSLoader.cpp in Mozilla Firefox 3.0.x before 3.0.18, 3.5.x before 3.5.8, and 3.6.x before 3.6.2; Thunderbird before 3.0.2; and SeaMonkey before 2.0.3 changes the case of certain strings in a stylesheet before adding this stylesheet to the XUL cache, which might allow remote attackers to modify the browser"s font and other CSS attributes, and potentially disrupt rendering of a web page, by forcing the browser to perform this erroneous stylesheet caching. | Assigned (20100106) | None (candidate not yet proposed) | View | |
43009 | CVE-2010-0425 | Candidate | modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2.3.x before 2.3.7, when running on Windows, does not ensure that request processing is complete before calling isapi_unload for an ISAPI .dll module, which allows remote attackers to execute arbitrary code via unspecified vectors related to a crafted request, a reset packet, and "orphaned callback pointers." | Assigned (20100127) | None (candidate not yet proposed) | View | |
43265 | CVE-2010-0681 | Candidate | ZeusCMS 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain sensitive information via a direct request for admin/backup.sql. | Assigned (20100222) | None (candidate not yet proposed) | View |
Page 142 of 20943, showing 5 records out of 104715 total, starting on record 706, ending on 710