CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42004  CVE-2009-4569  Candidate  SQL injection vulnerability in elkagroup Image Gallery allows remote attackers to execute arbitrary SQL commands via the id parameter to the default URI under news/.  Assigned (20100105)  None (candidate not yet proposed)    View
42260  CVE-2009-4825  Candidate  8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for App_Data/sb.mdb.  Assigned (20100427)  None (candidate not yet proposed)    View
42516  CVE-2009-5081  Candidate  The (1) config.guess, (2) contrib/groffer/perl/groffer.pl, and (3) contrib/groffer/perl/roff2.pl scripts in GNU troff (aka groff) 1.21 and earlier use an insufficient number of X characters in the template argument to the tempfile function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file, a different vulnerability than CVE-2004-0969.  Assigned (20110630)  None (candidate not yet proposed)    View
42772  CVE-2010-0188  Candidate  Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.  Assigned (20100106)  None (candidate not yet proposed)    View
43028  CVE-2010-0444  Candidate  HP Operations Agent 8.51, 8.52, 8.53, and 8.60 on Solaris 10 uses a blank password for the opc_op account, which allows remote attackers to execute arbitrary code via unspecified vectors.  Assigned (20100127)  None (candidate not yet proposed)    View

Page 1674 of 20943, showing 5 records out of 104715 total, starting on record 8366, ending on 8370

Actions