40948 |
CVE-2009-3513 |
Candidate |
Multiple cross-site scripting (XSS) vulnerabilities in Pilot Group (PG) eTraining allow remote attackers to inject arbitrary web script or HTML via (1) the cat_id parameter to courses_login.php, the id parameter to (2) news_read.php or (3) lessons_login.php, or (4) the cur parameter in a start action to lessons_login.php. |
Assigned (20091001) |
None (candidate not yet proposed) |
|
View
|
41204 |
CVE-2009-3769 |
Candidate |
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. |
Assigned (20091023) |
None (candidate not yet proposed) |
|
View
|
41460 |
CVE-2009-4025 |
Candidate |
Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: some of these details are obtained from third party information. |
Assigned (20091120) |
None (candidate not yet proposed) |
|
View
|
41716 |
CVE-2009-4281 |
Candidate |
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. |
Assigned (20091210) |
None (candidate not yet proposed) |
|
View
|
41972 |
CVE-2009-4537 |
Candidate |
drivers/net/r8169.c in the r8169 driver in the Linux kernel 2.6.32.3 and earlier does not properly check the size of an Ethernet frame that exceeds the MTU, which allows remote attackers to (1) cause a denial of service (temporary network outage) via a packet with a crafted size, in conjunction with certain packets containing A characters and certain packets containing E characters; or (2) cause a denial of service (system crash) via a packet with a crafted size, in conjunction with certain packets containing " |