CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40433  CVE-2009-2998  Candidate  Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-3458.  Assigned (20090827)  None (candidate not yet proposed)    View
40689  CVE-2009-3254  Candidate  Multiple stack-based buffer overflows in Ultimate Player 1.56 beta allow remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .upl playlist file.  Assigned (20090918)  None (candidate not yet proposed)    View
40945  CVE-2009-3510  Candidate  SQL injection vulnerability in viewListing.php in linkSpheric 0.74 Beta 6 allows remote attackers to execute arbitrary SQL commands via the listID parameter.  Assigned (20091001)  None (candidate not yet proposed)    View
41201  CVE-2009-3766  Candidate  mutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject"s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.  Assigned (20091023)  None (candidate not yet proposed)    View
41457  CVE-2009-4022  Candidate  Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.  Assigned (20091120)  None (candidate not yet proposed)    View

Page 18685 of 20943, showing 5 records out of 104715 total, starting on record 93421, ending on 93425

Actions