CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
39403 | CVE-2009-1968 | Candidate | Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers to affect integrity via unknown vectors. NOTE: the previous information was obtained from the July 2009 CPU. Oracle has not commented on claims from an established researcher that this is cross-site scripting (XSS) via the search_p_groups parameter in search/query/search. | Assigned (20090608) | None (candidate not yet proposed) | View | |
39659 | CVE-2009-2224 | Candidate | Directory traversal vulnerability in ang/shared/flags.php in AN Guestbook 0.7.8, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the g_lang parameter. | Assigned (20090626) | None (candidate not yet proposed) | View | |
39915 | CVE-2009-2480 | Candidate | Cross-site scripting (XSS) vulnerability in mt-wizard.cgi in Six Apart Movable Type 4.24, and 4.25 when global templates are not initialized, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20090716) | None (candidate not yet proposed) | View | |
40171 | CVE-2009-2736 | Candidate | Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators to inject arbitrary PHP code into config.php via the "Overall Width" field in a setconfig action. | Assigned (20090810) | None (candidate not yet proposed) | View | |
40427 | CVE-2009-2992 | Candidate | An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 does not properly validate input, which allows attackers to cause a denial of service via unknown vectors. | Assigned (20090827) | None (candidate not yet proposed) | View |
Page 19321 of 20943, showing 5 records out of 104715 total, starting on record 96601, ending on 96605