CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
42262 | CVE-2009-4827 | Candidate | Cross-site request forgery (CSRF) vulnerability in admin.php in Mail Manager Pro allows remote attackers to hijack the authentication of administrators for requests that change the admin password via a change action. | Assigned (20100427) | None (candidate not yet proposed) | View | |
42518 | CVE-2009-5083 | Candidate | IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when configured as an OpenID relying party, does not perform the expected login rejection upon receiving an OP-Identifier from an OpenID provider, which allows remote attackers to bypass authentication via unspecified vectors. | Assigned (20110812) | None (candidate not yet proposed) | View | |
42774 | CVE-2010-0190 | Candidate | Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20100106) | None (candidate not yet proposed) | View | |
43030 | CVE-2010-0446 | Candidate | Unspecified vulnerability on the HP DreamScreen 100 and 130 with firmware before 1.6.0.0, when using a web-connected configuration, allows remote attackers to obtain sensitive information via unknown vectors. | Assigned (20100127) | None (candidate not yet proposed) | View | |
43286 | CVE-2010-0702 | Candidate | SQL injection vulnerability in cisco/services/PhonecDirectory.php in Fonality Trixbox 2.2.4 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | Assigned (20100223) | None (candidate not yet proposed) | View |
Page 1812 of 20943, showing 5 records out of 104715 total, starting on record 9056, ending on 9060