CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42262  CVE-2009-4827  Candidate  Cross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a change action.  Assigned (20100427)  None (candidate not yet proposed)    View
42518  CVE-2009-5083  Candidate  IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID relying party, does not perform the expected login rejection upon receiving an OP-Identifier from an OpenID provider, which allows remote attackers to bypass authentication via unspecified vectors.  Assigned (20110812)  None (candidate not yet proposed)    View
42774  CVE-2010-0190  Candidate  Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20100106)  None (candidate not yet proposed)    View
43030  CVE-2010-0446  Candidate  Unspecified vulnerability on the HP DreamScreen 100 and 130 with firmware before 1.6.0.0, when using a web-connected configuration, allows remote attackers to obtain sensitive information via unknown vectors.  Assigned (20100127)  None (candidate not yet proposed)    View
43286  CVE-2010-0702  Candidate  SQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter.  Assigned (20100223)  None (candidate not yet proposed)    View

Page 1812 of 20943, showing 5 records out of 104715 total, starting on record 9056, ending on 9060

Actions