CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41749  CVE-2009-4314  Candidate  Sun Ray Server Software 4.1 on Solaris 10, when Automatic Multi-Group Hotdesking (AMGH) is enabled, responds to a logout action by immediately logging the user in again, which makes it easier for physically proximate attackers to obtain access to a session by going to an unattended DTU device.  Assigned (20091214)  None (candidate not yet proposed)    View
42005  CVE-2009-4570  Candidate  Cross-site scripting (XSS) vulnerability in PhpShop 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in an order/order_print action to the default URI.  Assigned (20100105)  None (candidate not yet proposed)    View
42261  CVE-2009-4826  Candidate  Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack the authentication of administrators for requests that alter administrative settings via a cp action.  Assigned (20100427)  None (candidate not yet proposed)    View
42517  CVE-2009-5082  Candidate  The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file.  Assigned (20110630)  None (candidate not yet proposed)    View
42773  CVE-2010-0189  Candidate  A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a crafted name for a download site.  Assigned (20100106)  None (candidate not yet proposed)    View

Page 1713 of 20943, showing 5 records out of 104715 total, starting on record 8561, ending on 8565

Actions