CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40689  CVE-2009-3254  Candidate  Multiple stack-based buffer overflows in Ultimate Player 1.56 beta allow remote attackers to execute arbitrary code via a long string in a (1) .m3u or (2) .upl playlist file.  Assigned (20090918)  None (candidate not yet proposed)    View
40945  CVE-2009-3510  Candidate  SQL injection vulnerability in viewListing.php in linkSpheric 0.74 Beta 6 allows remote attackers to execute arbitrary SQL commands via the listID parameter.  Assigned (20091001)  None (candidate not yet proposed)    View
41201  CVE-2009-3766  Candidate  mutt_ssl.c in mutt 1.5.16 and other versions before 1.5.19, when OpenSSL is used, does not verify the domain name in the subject"s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.  Assigned (20091023)  None (candidate not yet proposed)    View
41457  CVE-2009-4022  Candidate  Unspecified vulnerability in ISC BIND 9.0.x through 9.3.x, 9.4 before 9.4.3-P4, 9.5 before 9.5.2-P1, 9.6 before 9.6.1-P2, and 9.7 beta before 9.7.0b3, with DNSSEC validation enabled and checking disabled (CD), allows remote attackers to conduct DNS cache poisoning attacks by receiving a recursive client query and sending a response that contains an Additional section with crafted data, which is not properly handled when the response is processed "at the same time as requesting DNSSEC records (DO)," aka Bug 20438.  Assigned (20091120)  None (candidate not yet proposed)    View
41713  CVE-2009-4278  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20091210)  None (candidate not yet proposed)    View

Page 19811 of 20943, showing 5 records out of 104715 total, starting on record 99051, ending on 99055

Actions