CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40981  CVE-2009-3546  Candidate  The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information.  Assigned (20091005)  None (candidate not yet proposed)    View
41237  CVE-2009-3802  Candidate  Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") to _admin/index.php, which reveals the installation path and other information in an error message.  Assigned (20091027)  None (candidate not yet proposed)    View
41493  CVE-2009-4058  Candidate  SQL injection vulnerability in allauctions.php in Telebid Auction Script allows remote attackers to execute arbitrary SQL commands via the aid parameter.  Assigned (20091123)  None (candidate not yet proposed)    View
41749  CVE-2009-4314  Candidate  Sun Ray Server Software 4.1 on Solaris 10, when Automatic Multi-Group Hotdesking (AMGH) is enabled, responds to a logout action by immediately logging the user in again, which makes it easier for physically proximate attackers to obtain access to a session by going to an unattended DTU device.  Assigned (20091214)  None (candidate not yet proposed)    View
42005  CVE-2009-4570  Candidate  Cross-site scripting (XSS) vulnerability in PhpShop 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in an order/order_print action to the default URI.  Assigned (20100105)  None (candidate not yet proposed)    View

Page 1731 of 20943, showing 5 records out of 104715 total, starting on record 8651, ending on 8655

Actions