CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41962  CVE-2009-4527  Candidate  The Shibboleth authentication module 5.x before 5.x-3.4 and 6.x before 6.x-3.2, a module for Drupal, does not properly remove statically granted privileges after a logout or other session change, which allows physically proximate attackers to gain privileges by using an unattended web browser.  Assigned (20091231)  None (candidate not yet proposed)    View
42218  CVE-2009-4783  Candidate  Multiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL commands via the start parameter to (1) forum.php and (2) thread.php in community/, and (3) blog/index.php.  Assigned (20100421)  None (candidate not yet proposed)    View
42474  CVE-2009-5039  Candidate  Memory leak in the gk_circuit_info_do_in_acf function in the H.323 implementation in Cisco IOS before 15.0(1)XA allows remote attackers to cause a denial of service (memory consumption) via a large number of calls over a long duration, as demonstrated by InterZone Clear Token (IZCT) test traffic, aka Bug ID CSCsz72535.  Assigned (20110107)  None (candidate not yet proposed)    View
42730  CVE-2010-0146  Candidate  Directory traversal vulnerability in the Management Center for Cisco Security Agents 6.0 allows remote authenticated users to read arbitrary files via unspecified vectors.  Assigned (20100104)  None (candidate not yet proposed)    View
42986  CVE-2010-0402  Candidate  OpenTTD before 1.0.1 does not properly validate index values of certain items, which allows remote authenticated users to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted in-game command.  Assigned (20100127)  None (candidate not yet proposed)    View

Page 19255 of 20943, showing 5 records out of 104715 total, starting on record 96271, ending on 96275

Actions