CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40680  CVE-2009-3245  Candidate  OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors.  Assigned (20090918)  None (candidate not yet proposed)    View
40936  CVE-2009-3501  Candidate  SQL injection vulnerability in students.php in BPowerHouse BPStudents 1.0 allows remote attackers to execute arbitrary SQL commands via the test parameter in a preview action.  Assigned (20090930)  None (candidate not yet proposed)    View
41192  CVE-2009-3757  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to inject arbitrary web script or HTML via the (1) username parameter to config/edituser.php; (2) location, (3) sessionid, and (4) vmname parameters to console.php; (5) vmrefid and (6) vmname parameters to forcerestart.php; and (7) vmname and (8) vmrefid parameters to forcesd.php. NOTE: some of these details are obtained from third party information.  Assigned (20091022)  None (candidate not yet proposed)    View
41448  CVE-2009-4013  Candidate  Multiple directory traversal vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to overwrite arbitrary files or obtain sensitive information via vectors involving (1) control field names, (2) control field values, and (3) control files of patch systems.  Assigned (20091119)  None (candidate not yet proposed)    View
41704  CVE-2009-4269  Candidate  The password hash generation algorithm in the BUILTIN authentication functionality for Apache Derby before 10.6.1.0 performs a transformation that reduces the size of the set of inputs to SHA-1, which produces a small search space that makes it easier for local and possibly remote attackers to crack passwords by generating hash collisions, related to password substitution.  Assigned (20091210)  None (candidate not yet proposed)    View

Page 19094 of 20943, showing 5 records out of 104715 total, starting on record 95466, ending on 95470

Actions