CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40942  CVE-2009-3507  Candidate  Directory traversal vulnerability in modules.php in CMSphp 0.21 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod_file parameter.  Assigned (20091001)  None (candidate not yet proposed)    View
41198  CVE-2009-3763  Candidate  Unspecified vulnerability in the Access Manager / OpenSSO component in Oracle OpenSSO Enterprise 7.1, 7, 2005Q4, and 8.0 allows remote attackers to affect integrity via unknown vectors.  Assigned (20091023)  None (candidate not yet proposed)    View
41454  CVE-2009-4019  Candidate  mysqld in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41 does not (1) properly handle errors during execution of certain SELECT statements with subqueries, and does not (2) preserve certain null_value flags during execution of statements that use the GeomFromWKB function, which allows remote authenticated users to cause a denial of service (daemon crash) via a crafted statement.  Assigned (20091120)  None (candidate not yet proposed)    View
41710  CVE-2009-4275  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20091210)  None (candidate not yet proposed)    View
41966  CVE-2009-4531  Candidate  httpdx 1.4.4 and earlier allows remote attackers to obtain the source code for a web page by appending a . (dot) character to the URI.  Assigned (20091231)  None (candidate not yet proposed)    View

Page 19572 of 20943, showing 5 records out of 104715 total, starting on record 97856, ending on 97860

Actions