CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41748  CVE-2009-4313  Candidate  ir32_32.dll 3.24.15.3 in the Indeo32 codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (heap corruption) or execute arbitrary code via malformed data in a stream in a media file, as demonstrated by an AVI file.  Assigned (20091212)  None (candidate not yet proposed)    View
42004  CVE-2009-4569  Candidate  SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI under news/.  Assigned (20100105)  None (candidate not yet proposed)    View
42260  CVE-2009-4825  Candidate  8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for App_Data/sb.mdb.  Assigned (20100427)  None (candidate not yet proposed)    View
42516  CVE-2009-5081  Candidate  The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969.  Assigned (20110630)  None (candidate not yet proposed)    View
42772  CVE-2010-0188  Candidate  Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.  Assigned (20100106)  None (candidate not yet proposed)    View

Page 1636 of 20943, showing 5 records out of 104715 total, starting on record 8176, ending on 8180

Actions