CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40211  CVE-2009-2776  Candidate  SQL injection vulnerability in showresult.asp in Smart ASP Survey allows remote attackers to execute arbitrary SQL commands via the catid parameter.  Assigned (20090814)  None (candidate not yet proposed)    View
40467  CVE-2009-3032  Candidate  Integer overflow in kvolefio.dll 8.5.0.8339 and 10.5.0.0 in the Autonomy KeyView Filter SDK, as used in IBM Lotus Notes 8.5, Symantec Mail Security for Microsoft Exchange 5.0.10 through 5.0.13, and other products, allows context-dependent attackers to execute arbitrary code via a crafted OLE document that triggers a heap-based buffer overflow.  Assigned (20090831)  None (candidate not yet proposed)    View
40723  CVE-2009-3288  Candidate  The sg_build_indirect function in drivers/scsi/sg.c in Linux kernel 2.6.28-rc1 through 2.6.31-rc8 uses an incorrect variable when accessing an array, which allows local users to cause a denial of service (kernel OOPS and NULL pointer dereference), as demonstrated by using xcdroast to duplicate a CD. NOTE: this is only exploitable by users who can open the cdrom device.  Assigned (20090922)  None (candidate not yet proposed)    View
40979  CVE-2009-3544  Candidate  Xerver HTTP Server 4.32 allows remote attackers to obtain the source code for a web page via an HTTP request with the addition of ::$DATA after the HTML file name.  Assigned (20091005)  None (candidate not yet proposed)    View
41235  CVE-2009-3800  Candidate  Multiple unspecified vulnerabilities in Adobe Flash Player before 10.0.42.34 and Adobe AIR before 1.5.3 allow attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.  Assigned (20091026)  None (candidate not yet proposed)    View

Page 1558 of 20943, showing 5 records out of 104715 total, starting on record 7786, ending on 7790

Actions