CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41967  CVE-2009-4532  Candidate  Cross-site scripting (XSS) vulnerability in the Webform module 5.x before 5.x-2.8 and 6.x before 6.x-2.8, a module for Drupal, allows remote authenticated users, with webform creation privileges, to inject arbitrary web script or HTML via a field label.  Assigned (20091231)  None (candidate not yet proposed)    View
42223  CVE-2009-4788  Candidate  Multiple open redirect vulnerabilities in Pligg 1.0.2 and earlier allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the (1) return parameter to pligg/login.php and the (2) HTTP Referer header to user_settings.php.  Assigned (20100421)  None (candidate not yet proposed)    View
42479  CVE-2009-5044  Candidate  contrib/pdfmark/pdfroff.sh in GNU troff (aka groff) before 1.21 allows local users to overwrite arbitrary files via a symlink attack on a pdf#####.tmp temporary file.  Assigned (20110114)  None (candidate not yet proposed)    View
42735  CVE-2010-0151  Candidate  The Cisco Firewall Services Module (FWSM) 4.0 before 4.0(8), as used in for the Cisco Catalyst 6500 switches, Cisco 7600 routers, and ASA 5500 Adaptive Security Appliances, allows remote attackers to cause a denial of service (crash) via a malformed Skinny Client Control Protocol (SCCP) message.  Assigned (20100104)  None (candidate not yet proposed)    View
42991  CVE-2010-0407  Candidate  Multiple buffer overflows in the MSGFunctionDemarshall function in winscard_svc.c in the PC/SC Smart Card daemon (aka PCSCD) in MUSCLE PCSC-Lite before 1.5.4 allow local users to gain privileges via crafted message data, which is improperly demarshalled.  Assigned (20100127)  None (candidate not yet proposed)    View

Page 19042 of 20943, showing 5 records out of 104715 total, starting on record 95206, ending on 95210

Actions