CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41963  CVE-2009-4528  Candidate  The Organic Groups (OG) Vocabulary module 6.x before 6.x-1.0 for Drupal allows remote authenticated group members to bypass intended access restrictions, and create, modify, or read a vocabulary, via unspecified vectors.  Assigned (20091231)  None (candidate not yet proposed)    View
42219  CVE-2009-4784  Candidate  SQL injection vulnerability in the Joaktree (com_joaktree) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the treeId parameter to index.php.  Assigned (20100421)  None (candidate not yet proposed)    View
42475  CVE-2009-5040  Candidate  CallManager Express (CME) on Cisco IOS before 15.0(1)XA allows remote authenticated users to cause a denial of service (device crash) by using an extension mobility (EM) phone to interact with the menu for SNR number changes, aka Bug ID CSCta63555.  Assigned (20110107)  None (candidate not yet proposed)    View
42731  CVE-2010-0147  Candidate  SQL injection vulnerability in the Management Center for Cisco Security Agents 5.1 before 5.1.0.117, 5.2 before 5.2.0.296, and 6.0 before 6.0.1.132 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.  Assigned (20100104)  None (candidate not yet proposed)    View
42987  CVE-2010-0403  Candidate  Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the app parameter.  Assigned (20100127)  None (candidate not yet proposed)    View

Page 19323 of 20943, showing 5 records out of 104715 total, starting on record 96611, ending on 96615

Actions