CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42261  CVE-2009-4826  Candidate  Cross-site request forgery (CSRF) vulnerability in hosting/admin_ac.php in ScriptsEz Mini Hosting Panel allows remote attackers to hijack the authentication of administrators for requests that alter administrative settings via a cp action.  Assigned (20100427)  None (candidate not yet proposed)    View
42517  CVE-2009-5082  Candidate  The (1) configure and (2) config.guess scripts in GNU troff (aka groff) 1.20.1 on Openwall GNU/*/Linux (aka Owl) improperly create temporary files upon a failure of the mktemp function, which makes it easier for local users to overwrite arbitrary files via a symlink attack on a temporary file.  Assigned (20110630)  None (candidate not yet proposed)    View
42773  CVE-2010-0189  Candidate  A certain ActiveX control in NOS Microsystems getPlus Download Manager (aka DLM or Downloader) 1.5.2.35, as used in Adobe Download Manager, improperly validates requests involving web sites that are not in subdomains, which allows remote attackers to force the download and installation of arbitrary programs via a crafted name for a download site.  Assigned (20100106)  None (candidate not yet proposed)    View
43029  CVE-2010-0445  Candidate  Unspecified vulnerability in HP Network Node Manager (NNM) 8.10, 8.11, 8.12, and 8.13 allows remote attackers to execute arbitrary commands via unknown vectors.  Assigned (20100127)  None (candidate not yet proposed)    View
43285  CVE-2010-0701  Candidate  SQL injection vulnerability in ForceChangePassword.jsp in Newgen Software OmniDocs allows remote attackers to execute arbitrary SQL commands via unspecified vectors.  Assigned (20100223)  None (candidate not yet proposed)    View

Page 1732 of 20943, showing 5 records out of 104715 total, starting on record 8656, ending on 8660

Actions