CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40938 | CVE-2009-3503 | Candidate | Multiple SQL injection vulnerabilities in search.aspx in BPowerHouse BPHolidayLettings 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) rid and (2) tid parameters. | Assigned (20090930) | None (candidate not yet proposed) | View | |
41194 | CVE-2009-3759 | Candidate | Multiple cross-site request forgery (CSRF) vulnerabilities in sample code in the XenServer Resource Kit in Citrix XenCenterWeb allow remote attackers to hijack the authentication of administrators for (1) requests that change the password via the username parameter to config/changepw.php or (2) stop a virtual machine via the stop_vmname parameter to hardstopvm.php. NOTE: some of these details are obtained from third party information. | Assigned (20091022) | None (candidate not yet proposed) | View | |
41450 | CVE-2009-4015 | Candidate | Lintian 1.23.x through 1.23.28, 1.24.x through 1.24.2.1, and 2.x before 2.3.2 allows remote attackers to execute arbitrary commands via shell metacharacters in filename arguments. | Assigned (20091119) | None (candidate not yet proposed) | View | |
41706 | CVE-2009-4271 | Candidate | The Linux kernel 2.6.9 through 2.6.17 on the x86_64 and amd64 platforms allows local users to cause a denial of service (panic) via a 32-bit application that calls mprotect on its Virtual Dynamic Shared Object (VDSO) page and then triggers a segmentation fault. | Assigned (20091210) | None (candidate not yet proposed) | View | |
41962 | CVE-2009-4527 | Candidate | The Shibboleth authentication module 5.x before 5.x-3.4 and 6.x before 6.x-3.2, a module for Drupal, does not properly remove statically granted privileges after a logout or other session change, which allows physically proximate attackers to gain privileges by using an unattended web browser. | Assigned (20091231) | None (candidate not yet proposed) | View |
Page 19269 of 20943, showing 5 records out of 104715 total, starting on record 96341, ending on 96345