CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40178  CVE-2009-2743  Candidate  IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sensitive information by reading the First Failure Data Capture (FFDC) log file.  Assigned (20090812)  None (candidate not yet proposed)    View
40434  CVE-2009-2999  Candidate  The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of service (application restart and network disconnection) via an SMS message containing a malformed WAP Push message that triggers an ArrayIndexOutOfBoundsException exception, possibly a related issue to CVE-2009-2656.  Assigned (20090827)  None (candidate not yet proposed)    View
40690  CVE-2009-3255  Candidate  SQL injection vulnerability in RASH Quote Management System (RQMS) 1.2.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an admin action to the default URI.  Assigned (20090918)  None (candidate not yet proposed)    View
40946  CVE-2009-3511  Candidate  Multiple PHP remote file inclusion vulnerabilities in justVisual 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the fs_jVroot parameter to (1) sites/site/pages/index.php, (2) sites/test/pages/contact.php, (3) system/pageTemplate.php, and (4) system/utilities.php.  Assigned (20091001)  None (candidate not yet proposed)    View
41202  CVE-2009-3767  Candidate  libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a "" character in a domain name in the subject"s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.  Assigned (20091023)  None (candidate not yet proposed)    View

Page 18762 of 20943, showing 5 records out of 104715 total, starting on record 93806, ending on 93810

Actions