CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
42263 | CVE-2009-4828 | Candidate | Cross-site request forgery (CSRF) vulnerability in administration/admins.php in Ad Manager Pro (aka AdManagerPro) 3.0 allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an admin_created action. NOTE: some of these details are obtained from third party information. | Assigned (20100427) | None (candidate not yet proposed) | View | |
42519 | CVE-2009-5084 | Candidate | IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when com.tivoli.am.fim.infocard.delegates.InfoCardSTSDelegate tracing is enabled, creates a cleartext log entry containing a password, which might allow local users to obtain sensitive information by reading the log data. | Assigned (20110812) | None (candidate not yet proposed) | View | |
42775 | CVE-2010-0191 | Candidate | Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified vectors, related to a "prefix protocol handler vulnerability." | Assigned (20100106) | None (candidate not yet proposed) | View | |
43031 | CVE-2010-0447 | Candidate | The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate requests, which allows remote attackers to execute arbitrary commands via vectors involving upload of a JSP document. | Assigned (20100127) | None (candidate not yet proposed) | View | |
43287 | CVE-2010-0703 | Candidate | Cross-site scripting (XSS) vulnerability in wa/auth in PortWise SSL VPN 4.6 allows remote attackers to inject arbitrary web script or HTML via the reloadFrame parameter. | Assigned (20100223) | None (candidate not yet proposed) | View |
Page 1891 of 20943, showing 5 records out of 104715 total, starting on record 9451, ending on 9455