CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40724 | CVE-2009-3289 | Candidate | The g_file_copy function in glib 2.0 sets the permissions of a target file to the permissions of a symbolic link (777), which allows user-assisted local users to modify files of other users, as demonstrated by using Nautilus to modify the permissions of the user home directory. | Assigned (20090922) | None (candidate not yet proposed) | View | |
40980 | CVE-2009-3545 | Candidate | DataWizard Technologies FtpXQ FTP Server 3.0 allows remote authenticated users to cause a denial of service (crash) via a long ABOR command. | Assigned (20091005) | None (candidate not yet proposed) | View | |
41236 | CVE-2009-3801 | Candidate | SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmpass (aka Password) parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | Assigned (20091027) | None (candidate not yet proposed) | View | |
41492 | CVE-2009-4057 | Candidate | SQL injection vulnerability in the inertialFATE iF Portfolio Nexus (com_if_nexus) component 1.1 for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an item action to index.php. | Assigned (20091123) | None (candidate not yet proposed) | View | |
41748 | CVE-2009-4313 | Candidate | ir32_32.dll 3.24.15.3 in the Indeo32 codec in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 allows remote attackers to cause a denial of service (heap corruption) or execute arbitrary code via malformed data in a stream in a media file, as demonstrated by an AVI file. | Assigned (20091212) | None (candidate not yet proposed) | View |
Page 1673 of 20943, showing 5 records out of 104715 total, starting on record 8361, ending on 8365