CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40937  CVE-2009-3502  Candidate  SQL injection vulnerability in music.php in BPowerHouse BPMusic 1.0 allows remote attackers to execute arbitrary SQL commands via the music_id parameter.  Assigned (20090930)  None (candidate not yet proposed)    View
41193  CVE-2009-3758  Candidate  SQL injection vulnerability in login.php in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: some of these details are obtained from third party information.  Assigned (20091022)  None (candidate not yet proposed)    View
41449  CVE-2009-4014  Candidate  Multiple format string vulnerabilities in Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allow remote attackers to have an unspecified impact via vectors involving (1) check scripts and (2) the Lintian::Schedule module.  Assigned (20091119)  None (candidate not yet proposed)    View
41705  CVE-2009-4270  Candidate  Stack-based buffer overflow in the errprintf function in base/gsmisc.c in ghostscript 8.64 through 8.70 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted PDF file, as originally reported for debug logging code in gdevcups.c in the CUPS output driver.  Assigned (20091210)  None (candidate not yet proposed)    View
41961  CVE-2009-4526  Candidate  The Send by e-mail sub-module in the Print (aka Printer, e-mail and PDF versions) module 5.x before 5.x-4.9 and 6.x before 6.x-1.9, a module for Drupal, does not properly enforce privilege requirements, which allows remote attackers to read page titles by requesting a "Send to friend" form.  Assigned (20091231)  None (candidate not yet proposed)    View

Page 19162 of 20943, showing 5 records out of 104715 total, starting on record 95806, ending on 95810

Actions