CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39188  CVE-2009-1753  Candidate  Coccinelle 0.1.7 allows local users to overwrite arbitrary files via a symlink attack on an unspecified "result file."  Assigned (20090521)  None (candidate not yet proposed)    View
39444  CVE-2009-2009  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.5, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) curdirpath parameter to main/document/slideshow.php and the (2) file parameter to main/exercice/testheaderpage.php.  Assigned (20090608)  None (candidate not yet proposed)    View
39700  CVE-2009-2265  Candidate  Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable files in arbitrary directories via directory traversal sequences in the input to unspecified connector modules, as exploited in the wild for remote code execution in July 2009, related to the file browser and the editor/filemanager/connectors/ directory.  Assigned (20090629)  None (candidate not yet proposed)    View
39956  CVE-2009-2521  Candidate  Stack consumption vulnerability in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 7.0 allows remote authenticated users to cause a denial of service (daemon crash) via a list (ls) -R command containing a wildcard that references a subdirectory, followed by a .. (dot dot), aka "IIS FTP Service DoS Vulnerability."  Assigned (20090717)  None (candidate not yet proposed)    View
40212  CVE-2009-2777  Candidate  SQL injection vulnerability in visitor/view.php in GarageSales Script allows remote attackers to execute arbitrary SQL commands via the key parameter.  Assigned (20090814)  None (candidate not yet proposed)    View

Page 1634 of 20943, showing 5 records out of 104715 total, starting on record 8166, ending on 8170

Actions