CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
39666 | CVE-2009-2231 | Candidate | MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record in a MIDAS cookie. | Assigned (20090626) | None (candidate not yet proposed) | View | |
39922 | CVE-2009-2487 | Candidate | Use-after-free vulnerability in the frpr_icmp function in the ipfilter (aka IP Filter) subsystem in Sun Solaris 10, and OpenSolaris snv_45 through snv_110, allows remote attackers to cause a denial of service (panic) via unspecified vectors. | Assigned (20090716) | None (candidate not yet proposed) | View | |
40178 | CVE-2009-2743 | Candidate | IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.27, and 7.0 before 7.0.0.7, does not properly handle an exception occurring after use of wsadmin scripts and configuration of JAAS-J2C Authentication Data, which allows local users to obtain sensitive information by reading the First Failure Data Capture (FFDC) log file. | Assigned (20090812) | None (candidate not yet proposed) | View | |
40434 | CVE-2009-2999 | Candidate | The com.android.phone process in Android 1.5 CRBxx allows remote attackers to cause a denial of service (application restart and network disconnection) via an SMS message containing a malformed WAP Push message that triggers an ArrayIndexOutOfBoundsException exception, possibly a related issue to CVE-2009-2656. | Assigned (20090827) | None (candidate not yet proposed) | View | |
40690 | CVE-2009-3255 | Candidate | SQL injection vulnerability in RASH Quote Management System (RQMS) 1.2.2 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the user parameter in an admin action to the default URI. | Assigned (20090918) | None (candidate not yet proposed) | View |
Page 19885 of 20943, showing 5 records out of 104715 total, starting on record 99421, ending on 99425