CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39658  CVE-2009-2223  Candidate  Directory traversal vulnerability in locms/smarty.php in LightOpenCMS 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cwd parameter. NOTE: remote file inclusion attacks may be possible.  Assigned (20090626)  None (candidate not yet proposed)    View
39914  CVE-2009-2479  Candidate  Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exception and application crash) via a long Unicode string argument to the write method. NOTE: this was originally reported as a stack-based buffer overflow. NOTE: on Linux and Mac OS X, a crash resulting from this long string reportedly occurs in an operating-system library, not in Firefox.  Assigned (20090716)  None (candidate not yet proposed)    View
40170  CVE-2009-2735  Candidate  SQL injection vulnerability in admin.php in sun-jester OpenNews 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.  Assigned (20090810)  None (candidate not yet proposed)    View
40426  CVE-2009-2991  Candidate  Unspecified vulnerability in the Mozilla plug-in in Adobe Reader and Acrobat 8.x before 8.1.7, and possibly 7.x before 7.1.4 and 9.x before 9.2, might allow remote attackers to execute arbitrary code via unknown vectors.  Assigned (20090827)  None (candidate not yet proposed)    View
40682  CVE-2009-3247  Candidate  Cross-site scripting (XSS) vulnerability in the Activities module in vtiger CRM 5.0.4 allows remote attackers to inject arbitrary web script or HTML via the action parameter to phprint.php. NOTE: the query_string vector is already covered by CVE-2008-3101.3.  Assigned (20090918)  None (candidate not yet proposed)    View

Page 19268 of 20943, showing 5 records out of 104715 total, starting on record 96336, ending on 96340

Actions