CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
41962 | CVE-2009-4527 | Candidate | The Shibboleth authentication module 5.x before 5.x-3.4 and 6.x before 6.x-3.2, a module for Drupal, does not properly remove statically granted privileges after a logout or other session change, which allows physically proximate attackers to gain privileges by using an unattended web browser. | Assigned (20091231) | None (candidate not yet proposed) | View | |
42218 | CVE-2009-4783 | Candidate | Multiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL commands via the start parameter to (1) forum.php and (2) thread.php in community/, and (3) blog/index.php. | Assigned (20100421) | None (candidate not yet proposed) | View | |
42474 | CVE-2009-5039 | Candidate | Memory leak in the gk_circuit_info_do_in_acf function in the H.323 implementation in Cisco IOS before 15.0(1)XA allows remote attackers to cause a denial of service (memory consumption) via a large number of calls over a long duration, as demonstrated by InterZone Clear Token (IZCT) test traffic, aka Bug ID CSCsz72535. | Assigned (20110107) | None (candidate not yet proposed) | View | |
42730 | CVE-2010-0146 | Candidate | Directory traversal vulnerability in the Management Center for Cisco Security Agents 6.0 allows remote authenticated users to read arbitrary files via unspecified vectors. | Assigned (20100104) | None (candidate not yet proposed) | View | |
42986 | CVE-2010-0402 | Candidate | OpenTTD before 1.0.1 does not properly validate index values of certain items, which allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted in-game command. | Assigned (20100127) | None (candidate not yet proposed) | View |
Page 19255 of 20943, showing 5 records out of 104715 total, starting on record 96271, ending on 96275