CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40468  CVE-2009-3033  Candidate  Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilities.dll in the web console in Symantec Altiris Deployment Solution 6.9.x, Altiris Notification Server 6.0.x, and Management Platform 7.0.x allows remote attackers to execute arbitrary code via a long string in the second argument.  Assigned (20090831)  None (candidate not yet proposed)    View
40724  CVE-2009-3289  Candidate  The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory.  Assigned (20090922)  None (candidate not yet proposed)    View
40980  CVE-2009-3545  Candidate  DataWizard Technologies FtpXQ FTP Server 3.0 allows remote authenticated users to cause a denial of service (crash) via a long ABOR command.  Assigned (20091005)  None (candidate not yet proposed)    View
41236  CVE-2009-3801  Candidate  SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmpass (aka Password) parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20091027)  None (candidate not yet proposed)    View
41492  CVE-2009-4057  Candidate  SQL injection vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an item action to index.php.  Assigned (20091123)  None (candidate not yet proposed)    View

Page 1651 of 20943, showing 5 records out of 104715 total, starting on record 8251, ending on 8255

Actions