CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41450  CVE-2009-4015  Candidate  Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitrary commands via shell metacharacters in filename arguments.  Assigned (20091119)  None (candidate not yet proposed)    View
41706  CVE-2009-4271  Candidate  The Linux kernel 2.6.9 through 2.6.17 on the x86_64 and amd64 platforms allows local users to cause a denial of service (panic) via a 32-bit application that calls mprotect on its Virtual Dynamic Shared Object (VDSO) page and then triggers a segmentation fault.  Assigned (20091210)  None (candidate not yet proposed)    View
41962  CVE-2009-4527  Candidate  The Shibboleth authentication module 5.x before 5.x-3.4 and 6.x before 6.x-3.2, a module for Drupal, does not properly remove statically granted privileges after a logout or other session change, which allows physically proximate attackers to gain privileges by using an unattended web browser.  Assigned (20091231)  None (candidate not yet proposed)    View
42218  CVE-2009-4783  Candidate  Multiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL commands via the start parameter to (1) forum.php and (2) thread.php in community/, and (3) blog/index.php.  Assigned (20100421)  None (candidate not yet proposed)    View
42474  CVE-2009-5039  Candidate  Memory leak in the gk_circuit_info_do_in_acf function in the H.323 implementation in Cisco IOS before 15.0(1)XA allows remote attackers to cause a denial of service (memory consumption) via a large number of calls over a long duration, as demonstrated by InterZone Clear Token (IZCT) test traffic, aka Bug ID CSCsz72535.  Assigned (20110107)  None (candidate not yet proposed)    View

Page 18644 of 20943, showing 5 records out of 104715 total, starting on record 93216, ending on 93220

Actions