CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
39188 | CVE-2009-1753 | Candidate | Coccinelle 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on an unspecified "result file." | Assigned (20090521) | None (candidate not yet proposed) | View | |
39444 | CVE-2009-2009 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) curdirpath parameter to main/document/slideshow.php and the (2) file parameter to main/exercice/testheaderpage.php. | Assigned (20090608) | None (candidate not yet proposed) | View | |
39700 | CVE-2009-2265 | Candidate | Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory. | Assigned (20090629) | None (candidate not yet proposed) | View | |
39956 | CVE-2009-2521 | Candidate | Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka "IIS FTP Service DoS Vulnerability." | Assigned (20090717) | None (candidate not yet proposed) | View | |
40212 | CVE-2009-2777 | Candidate | SQL injection vulnerability in visitor/view.php in GarageSales Script allows remote attackers to execute arbitrary SQL commands via the key parameter. | Assigned (20090814) | None (candidate not yet proposed) | View |
Page 1634 of 20943, showing 5 records out of 104715 total, starting on record 8166, ending on 8170