CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41453  CVE-2009-4018  Candidate  The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute programs with an arbitrary environment via the env parameter, as demonstrated by a crafted value of the LD_LIBRARY_PATH environment variable.  Assigned (20091120)  None (candidate not yet proposed)    View
41709  CVE-2009-4274  Candidate  Stack-based buffer overflow in converter/ppm/xpmtoppm.c in netpbm before 10.47.07 allows context-dependent attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an XPM image file that contains a crafted header field associated with a large color index value.  Assigned (20091210)  None (candidate not yet proposed)    View
41965  CVE-2009-4530  Candidate  Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending ::$DATA to the URI.  Assigned (20091231)  None (candidate not yet proposed)    View
42221  CVE-2009-4786  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Pligg before 1.0.3 allow remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to (1) admin/admin_config.php, (2) admin/admin_modules.php, (3) delete.php, (4) editlink.php, (5) submit.php, (6) submit_groups.php, (7) user_add_remove_links.php, and (8) user_settings.php.  Assigned (20100421)  None (candidate not yet proposed)    View
42477  CVE-2009-5042  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20110114)  None (candidate not yet proposed)    View

Page 19501 of 20943, showing 5 records out of 104715 total, starting on record 97501, ending on 97505

Actions