CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40436  CVE-2009-3001  Candidate  The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel 2.6.31-rc7 and earlier does not initialize a certain data structure, which allows local users to read the contents of some kernel memory locations by calling getsockname on an AF_LLC socket.  Assigned (20090828)  None (candidate not yet proposed)    View
40692  CVE-2009-3257  Candidate  vtiger CRM before 5.1.0 allows remote authenticated users to bypass the permissions on the (1) Account Billing Address and (2) Shipping Address fields in a profile by creating a Sales Order (SO) associated with that profile.  Assigned (20090918)  None (candidate not yet proposed)    View
40948  CVE-2009-3513  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in Pilot Group (PG) eTraining allow remote attackers to inject arbitrary web script or HTML via (1) the cat_id parameter to courses_login.php, the id parameter to (2) news_read.php or (3) lessons_login.php, or (4) the cur parameter in a start action to lessons_login.php.  Assigned (20091001)  None (candidate not yet proposed)    View
41204  CVE-2009-3769  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20091023)  None (candidate not yet proposed)    View
41460  CVE-2009-4025  Candidate  Argument injection vulnerability in the traceroute function in Traceroute.php in the Net_Traceroute package before 0.21.2 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: some of these details are obtained from third party information.  Assigned (20091120)  None (candidate not yet proposed)    View

Page 20049 of 20943, showing 5 records out of 104715 total, starting on record 100241, ending on 100245

Actions