CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40177  CVE-2009-2742  Candidate  Cross-site scripting (XSS) vulnerability in Eclipse Help in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27 allows remote attackers to inject arbitrary web script or HTML via unspecified input.  Assigned (20090812)  None (candidate not yet proposed)    View
40433  CVE-2009-2998  Candidate  Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-3458.  Assigned (20090827)  None (candidate not yet proposed)    View
40689  CVE-2009-3254  Candidate  Multiple stack-based buffer overflows in Ultimate Player 1.56 beta allow remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .upl playlist file.  Assigned (20090918)  None (candidate not yet proposed)    View
40945  CVE-2009-3510  Candidate  SQL injection vulnerability in viewListing.php in linkSpheric 0.74 Beta 6 allows remote attackers to execute arbitrary SQL commands via the listID parameter.  Assigned (20091001)  None (candidate not yet proposed)    View
41201  CVE-2009-3766  Candidate  mutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject"s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.  Assigned (20091023)  None (candidate not yet proposed)    View

Page 19200 of 20943, showing 5 records out of 104715 total, starting on record 95996, ending on 96000

Actions