CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40210  CVE-2009-2775  Candidate  SQL injection vulnerability in linkout.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20090814)  None (candidate not yet proposed)    View
40466  CVE-2009-3031  Candidate  Stack-based buffer overflow in the BrowseAndSaveFile method in the Altiris eXpress NS ConsoleUtilities ActiveX control 6.0.0.1846 in AeXNSConsoleUtilities.dll in Symantec Altiris Notification Server (NS) 6.0 before R12, Deployment Server 6.8 and 6.9 in Symantec Altiris Deployment Solution 6.9 SP3, and Symantec Management Platform (SMP) 7.0 before SP3 allows remote attackers to execute arbitrary code via a long string in the second argument.  Assigned (20090831)  None (candidate not yet proposed)    View
40722  CVE-2009-3287  Candidate  lib/thin/connection.rb in Thin web server before 1.2.4 relies on the X-Forwarded-For header to determine the IP address of the client, which allows remote attackers to spoof the IP address and hide activities via a modified X-Forwarded-For header.  Assigned (20090922)  None (candidate not yet proposed)    View
40978  CVE-2009-3543  Candidate  SQL injection vulnerability in _phenotype/admin/login.php in Phenotype CMS before 2.9 allows remote attackers to execute arbitrary SQL commands via the user parameter (aka the login name).  Assigned (20091002)  None (candidate not yet proposed)    View
41234  CVE-2009-3799  Candidate  Integer overflow in the Verifier::parseExceptionHandlers function in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allows remote attackers to execute arbitrary code via an SWF file with a large exception_count value that triggers memory corruption, related to "generation of ActionScript exception handlers."  Assigned (20091026)  None (candidate not yet proposed)    View

Page 1492 of 20943, showing 5 records out of 104715 total, starting on record 7456, ending on 7460

Actions