CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
39395 | CVE-2009-1960 | Candidate | inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via the config_cascade[main][default][] parameter to doku.php. NOTE: PHP remote file inclusion is also possible in PHP 5 using ftp:// URLs. | Assigned (20090606) | None (candidate not yet proposed) | View | |
39651 | CVE-2009-2216 | Candidate | Cross-site scripting (XSS) vulnerability in CMD_REDIRECT in DirectAdmin 1.33.6 and earlier allows remote attackers to inject arbitrary web script or HTML via the URI in a view=advanced request. | Assigned (20090625) | None (candidate not yet proposed) | View | |
39907 | CVE-2009-2472 | Candidate | Mozilla Firefox before 3.0.12 does not always use XPCCrossOriginWrapper when required during object construction, which allows remote attackers to bypass the Same Origin Policy and conduct cross-site scripting (XSS) attacks via a crafted document, related to a "cross origin wrapper bypass." | Assigned (20090715) | None (candidate not yet proposed) | View | |
40163 | CVE-2009-2728 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20090810) | None (candidate not yet proposed) | View | |
40419 | CVE-2009-2984 | Candidate | Unspecified vulnerability in the image decoder in Adobe Acrobat 9.x before 9.2, and possibly 7.x through 7.1.4 and 8.x through 8.1.7, allows attackers to cause a denial of service or possibly execute arbitrary code via unknown vectors. | Assigned (20090827) | None (candidate not yet proposed) | View |
Page 18678 of 20943, showing 5 records out of 104715 total, starting on record 93386, ending on 93390