CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40685 | CVE-2009-3250 | Candidate | The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated users to execute arbitrary code by composing an e-mail message with an attachment filename ending in (1) .php in installations based on certain Apache HTTP Server configurations, (2) .php. on Windows, or (3) .php/ on Linux, and then making a direct request to a certain pathname under storage/. | Assigned (20090918) | None (candidate not yet proposed) | View | |
40941 | CVE-2009-3506 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in CMSphp 0.21 allow remote attackers to inject arbitrary web script or HTML via the (1) cook_user parameter to index.php and the (2) name parameter to modules.php. | Assigned (20091001) | None (candidate not yet proposed) | View | |
41197 | CVE-2009-3762 | Candidate | Unspecified vulnerability in Oracle OpenSSO Enterprise 8.0 allows remote attackers to affect integrity via unknown vectors. | Assigned (20091023) | None (candidate not yet proposed) | View | |
41453 | CVE-2009-4018 | Candidate | The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute programs with an arbitrary environment via the env parameter, as demonstrated by a crafted value of the LD_LIBRARY_PATH environment variable. | Assigned (20091120) | None (candidate not yet proposed) | View | |
41709 | CVE-2009-4274 | Candidate | Stack-based buffer overflow in converter/ppm/xpmtoppm.c in netpbm before 10.47.07 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an XPM image file that contains a crafted header field associated with a large color index value. | Assigned (20091210) | None (candidate not yet proposed) | View |
Page 19482 of 20943, showing 5 records out of 104715 total, starting on record 97406, ending on 97410