CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42227  CVE-2009-4792  Candidate  SQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote attackers to execute arbitrary SQL commands via the memid parameter to members.php.  Assigned (20100422)  None (candidate not yet proposed)    View
42483  CVE-2009-5048  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20110114)  None (candidate not yet proposed)    View
42739  CVE-2010-0155  Candidate  CRLF injection vulnerability in load.php in the Local Management Interface (LMI) on the IBM Proventia Network Mail Security System (PNMSS) appliance with firmware before 2.5 allows remote authenticated users to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the javaVersion parameter.  Assigned (20100104)  None (candidate not yet proposed)    View
42995  CVE-2010-0411  Candidate  Multiple integer signedness errors in the (1) __get_argv and (2) __get_compat_argv functions in tapset/aux_syscalls.stp in SystemTap 1.1 allow local users to cause a denial of service (script crash, or system crash or hang) via a process with a large number of arguments, leading to a buffer overflow.  Assigned (20100127)  None (candidate not yet proposed)    View
43251  CVE-2010-0667  Candidate  MoinMoin 1.9 before 1.9.1 does not perform the expected clearing of the sys.argv array in situations where the GATEWAY_INTERFACE environment variable is set, which allows remote attackers to obtain sensitive information via unspecified vectors.  Assigned (20100221)  None (candidate not yet proposed)    View

Page 19964 of 20943, showing 5 records out of 104715 total, starting on record 99816, ending on 99820

Actions