CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40427  CVE-2009-2992  Candidate  An unspecified ActiveX control in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 does not properly validate input, which allows attackers to cause a denial of service via unknown vectors.  Assigned (20090827)  None (candidate not yet proposed)    View
40683  CVE-2009-3248  Candidate  Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin users for requests that modify the news feed system via the rssurl parameter in a Save action to index.php.  Assigned (20090918)  None (candidate not yet proposed)    View
40939  CVE-2009-3504  Candidate  SQL injection vulnerability in offers_buy.php in Alibaba Clone 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.  Assigned (20090930)  None (candidate not yet proposed)    View
41195  CVE-2009-3760  Candidate  Static code injection vulnerability in config/writeconfig.php in the sample code in the XenServer Resource Kit in Citrix XenCenterWeb allows remote attackers to inject arbitrary PHP code into include/config.ini.php via the pool1 parameter. NOTE: some of these details are obtained from third party information.  Assigned (20091022)  None (candidate not yet proposed)    View
41451  CVE-2009-4016  Candidate  Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox before 2.2.9, and (3) oftc-hybrid before 1.6.8, when flatten_links is disabled, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a LINKS command.  Assigned (20091119)  None (candidate not yet proposed)    View

Page 19346 of 20943, showing 5 records out of 104715 total, starting on record 96726, ending on 96730

Actions