CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40981 | CVE-2009-3546 | Candidate | The _gdGetColors function in gd_gd.c in PHP 5.2.11 and 5.3.x before 5.3.1, and the GD Graphics Library 2.x, does not properly verify a certain colorsTotal structure member, which might allow remote attackers to conduct buffer overflow or buffer over-read attacks via a crafted GD file, a different vulnerability than CVE-2009-3293. NOTE: some of these details are obtained from third party information. | Assigned (20091005) | None (candidate not yet proposed) | View | |
41237 | CVE-2009-3802 | Candidate | Amiro.CMS 5.4.0.0 and earlier allows remote attackers to obtain sensitive information via an invalid loginname ("%%%") to _admin/index.php, which reveals the installation path and other information in an error message. | Assigned (20091027) | None (candidate not yet proposed) | View | |
41493 | CVE-2009-4058 | Candidate | SQL injection vulnerability in allauctions.php in Telebid Auction Script allows remote attackers to execute arbitrary SQL commands via the aid parameter. | Assigned (20091123) | None (candidate not yet proposed) | View | |
41749 | CVE-2009-4314 | Candidate | Sun Ray Server Software 4.1 on Solaris 10, when Automatic Multi-Group Hotdesking (AMGH) is enabled, responds to a logout action by immediately logging the user in again, which makes it easier for physically proximate attackers to obtain access to a session by going to an unattended DTU device. | Assigned (20091214) | None (candidate not yet proposed) | View | |
42005 | CVE-2009-4570 | Candidate | Cross-site scripting (XSS) vulnerability in PhpShop 0.8.1 allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in an order/order_print action to the default URI. | Assigned (20100105) | None (candidate not yet proposed) | View |
Page 1731 of 20943, showing 5 records out of 104715 total, starting on record 8651, ending on 8655