CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42263  CVE-2009-4828  Candidate  Cross-site request forgery (CSRF) vulnerability in administration/admins.php in Ad Manager Pro (aka AdManagerPro) 3.0 allows remote attackers to hijack the authentication of administrators for requests that create new administrative users via an admin_created action. NOTE: some of these details are obtained from third party information.  Assigned (20100427)  None (candidate not yet proposed)    View
42519  CVE-2009-5084  Candidate  IBM Tivoli Federated Identity Manager (TFIM) 6.2.0 before 6.2.0.2, when com.tivoli.am.fim.infocard.delegates.InfoCardSTSDelegate tracing is enabled, creates a cleartext log entry containing a password, which might allow local users to obtain sensitive information by reading the log data.  Assigned (20110812)  None (candidate not yet proposed)    View
42775  CVE-2010-0191  Candidate  Adobe Reader and Acrobat 9.x before 9.3.2, and 8.x before 8.2.2 on Windows and Mac OS X, allow attackers to execute arbitrary code via unspecified vectors, related to a "prefix protocol handler vulnerability."  Assigned (20100106)  None (candidate not yet proposed)    View
43031  CVE-2010-0447  Candidate  The helpmanager servlet in the web server in HP OpenView Performance Insight (OVPI) 5.4 and earlier does not properly authenticate and validate requests, which allows remote attackers to execute arbitrary commands via vectors involving upload of a JSP document.  Assigned (20100127)  None (candidate not yet proposed)    View
43287  CVE-2010-0703  Candidate  Cross-site scripting (XSS) vulnerability in wa/auth in PortWise SSL VPN 4.6 allows remote attackers to inject arbitrary web script or HTML via the reloadFrame parameter.  Assigned (20100223)  None (candidate not yet proposed)    View

Page 1891 of 20943, showing 5 records out of 104715 total, starting on record 9451, ending on 9455

Actions