CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40685  CVE-2009-3250  Candidate  The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail message with an attachment filename ending in (1) .php in installations based on certain Apache HTTP Server configurations, (2) .php. on Windows, or (3) .php/ on Linux, and then making a direct request to a certain pathname under storage/.  Assigned (20090918)  None (candidate not yet proposed)    View
40941  CVE-2009-3506  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in CMSphp 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) cook_user parameter to index.php and the (2) name parameter to modules.php.  Assigned (20091001)  None (candidate not yet proposed)    View
41197  CVE-2009-3762  Candidate  Unspecified vulnerability in Oracle OpenSSO Enterprise 8.0 allows remote attackers to affect integrity via unknown vectors.  Assigned (20091023)  None (candidate not yet proposed)    View
41453  CVE-2009-4018  Candidate  The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute programs with an arbitrary environment via the env parameter, as demonstrated by a crafted value of the LD_LIBRARY_PATH environment variable.  Assigned (20091120)  None (candidate not yet proposed)    View
41709  CVE-2009-4274  Candidate  Stack-based buffer overflow in converter/ppm/xpmtoppm.c in netpbm before 10.47.07 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an XPM image file that contains a crafted header field associated with a large color index value.  Assigned (20091210)  None (candidate not yet proposed)    View

Page 19482 of 20943, showing 5 records out of 104715 total, starting on record 97406, ending on 97410

Actions