CVE List

Id CVE No. Status Description Phase Votes Comments Actions
38902  CVE-2009-1467  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in IceWarp eMail Server and WebMail Server before 9.4.2 allow remote attackers to inject arbitrary web script or HTML via (1) the body of a message, related to the email view and incorrect HTML filtering in the cleanHTML function in server/inc/tools.php; or the (2) title, (3) link, or (4) description element in an RSS feed, related to the getHTML function in server/inc/rss/item.php.  Assigned (20090428)  None (candidate not yet proposed)    View
104438  CVE-2017-7618  Candidate  crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue.  Assigned (20170410)  None (candidate not yet proposed)    View
39158  CVE-2009-1723  Candidate  CFNetwork in Apple Mac OS X 10.5 before 10.5.8 places an incorrect URL in a certificate warning in certain 302 redirection scenarios, which makes it easier for remote attackers to trick a user into visiting an arbitrary https web site by leveraging an open redirect vulnerability, a different issue than CVE-2009-2062.  Assigned (20090520)  None (candidate not yet proposed)    View
104694  CVE-2017-7874  Candidate  udevd in udev 232, when the Linux kernel 4.8.0 is used, does not properly verify the source of a Netlink message, which allows local users to execute arbitrary commands by leveraging access to the NETLINK_KOBJECT_UEVENT family, and the presence of the /lib/udev/rules.d/50-udev-default.rules file, to provide a crafted REMOVE_CMD value.  Assigned (20170414)  None (candidate not yet proposed)    View
39414  CVE-2009-1979  Candidate  Unspecified vulnerability in the Network Authentication component in Oracle Database 10.1.0.5 and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previous information was obtained from the October 2009 CPU. Oracle has not commented on claims from an independent researcher that this is related to improper validation of the AUTH_SESSKEY parameter length that leads to arbitrary code execution.  Assigned (20090608)  None (candidate not yet proposed)    View

Page 20201 of 20943, showing 5 records out of 104715 total, starting on record 101001, ending on 101005

Actions