CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39692  CVE-2009-2257  Candidate  The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentication via a direct request to (1) gateway/commands/saveconfig.html, and (2) stattbl.htm, (3) modemmenu.htm, (4) onload.htm, (5) form.css, (6) utility.js, and possibly (7) indextop.htm in html/.  Assigned (20090629)  None (candidate not yet proposed)    View
39948  CVE-2009-2513  Candidate  The Graphics Device Interface (GDI) in win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2 does not properly validate user-mode input, which allows local users to gain privileges via a crafted application, aka "Win32k Insufficient Data Validation Vulnerability."  Assigned (20090717)  None (candidate not yet proposed)    View
40204  CVE-2009-2769  Candidate  PHP remote file inclusion vulnerability in include/timesheet.php in Ultrize TimeSheet 1.2.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[include_dir] parameter.  Assigned (20090814)  None (candidate not yet proposed)    View
40460  CVE-2009-3025  Candidate  Unspecified vulnerability in Pidgin 2.6.0 allows remote attackers to cause a denial of service (crash) via a link in a Yahoo IM.  Assigned (20090831)  None (candidate not yet proposed)    View
40716  CVE-2009-3281  Candidate  The vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 does not use correct file permissions, which allows host OS users to gain privileges on the host OS via unspecified vectors.  Assigned (20090921)  None (candidate not yet proposed)    View

Page 1627 of 20943, showing 5 records out of 104715 total, starting on record 8131, ending on 8135

Actions