CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40946  CVE-2009-3511  Candidate  Multiple PHP remote file inclusion vulnerabilities in justVisual 1.2 allow remote attackers to execute arbitrary PHP code via a URL in the fs_jVroot parameter to (1) sites/site/pages/index.php, (2) sites/test/pages/contact.php, (3) system/pageTemplate.php, and (4) system/utilities.php.  Assigned (20091001)  None (candidate not yet proposed)    View
41202  CVE-2009-3767  Candidate  libraries/libldap/tls_o.c in OpenLDAP 2.2 and 2.4, and possibly other versions, when OpenSSL is used, does not properly handle a "" character in a domain name in the subject"s Common Name (CN) field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.  Assigned (20091023)  None (candidate not yet proposed)    View
41458  CVE-2009-4023  Candidate  Argument injection vulnerability in the sendmail implementation of the Mail::Send method (Mail/sendmail.php) in the Mail package 1.1.14 for PEAR allows remote attackers to read and write arbitrary files via a crafted $from parameter, a different vector than CVE-2009-4111.  Assigned (20091120)  None (candidate not yet proposed)    View
41714  CVE-2009-4279  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20091210)  None (candidate not yet proposed)    View
41970  CVE-2009-4535  Candidate  Mongoose 2.8.0 and earlier allows remote attackers to obtain the source code for a web page by appending a / (slash) character to the URI.  Assigned (20091231)  None (candidate not yet proposed)    View

Page 19886 of 20943, showing 5 records out of 104715 total, starting on record 99426, ending on 99430

Actions