CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41698  CVE-2009-4263  Candidate  SQL injection vulnerability in main_forum.php in PTCPay GeN3 forum 1.3 allows remote attackers to execute arbitrary SQL commands via the cat parameter.  Assigned (20091210)  None (candidate not yet proposed)    View
41954  CVE-2009-4519  Candidate  Multiple unspecified vulnerabilities in Ortro before 1.3.4 have unknown impact and attack vectors.  Assigned (20091231)  None (candidate not yet proposed)    View
42210  CVE-2009-4775  Candidate  Format string vulnerability in Ipswitch WS_FTP Professional 12 before 12.2 allows remote attackers to cause a denial of service (crash) via format string specifiers in the status code portion of an HTTP response.  Assigned (20100421)  None (candidate not yet proposed)    View
42466  CVE-2009-5031  Candidate  ModSecurity before 2.5.11 treats request parameter values containing single quotes as files, which allows remote attackers to bypass filtering rules and perform other attacks such as cross-site scripting (XSS) attacks via a single quote in a request parameter in the Content-Disposition field of a request with a multipart/form-data Content-Type header.  Assigned (20101209)  None (candidate not yet proposed)    View
42722  CVE-2010-0138  Candidate  Buffer overflow in Cisco CiscoWorks Internetwork Performance Monitor (IPM) 2.6 and earlier on Windows, as distributed in CiscoWorks LAN Management Solution (LMS), allows remote attackers to execute arbitrary code via a malformed getProcessName CORBA General Inter-ORB Protocol (GIOP) request, related to a "third-party component," aka Bug ID CSCsv62350.  Assigned (20100104)  None (candidate not yet proposed)    View

Page 18652 of 20943, showing 5 records out of 104715 total, starting on record 93256, ending on 93260

Actions