CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39928  CVE-2009-2493  Candidate  The Active Template Library (ATL) in Microsoft Visual Studio .NET 2003 SP1, Visual Studio 2005 SP1 and 2008 Gold and SP1, and Visual C++ 2005 SP1 and 2008 Gold and SP1; and Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 Gold and SP2; does not properly restrict use of OleLoadFromStream in instantiating objects from data streams, which allows remote attackers to execute arbitrary code via a crafted HTML document with an ATL (1) component or (2) control, related to ATL headers and bypassing security policies, aka "ATL COM Initialization Vulnerability."  Assigned (20090717)  None (candidate not yet proposed)    View
40184  CVE-2009-2749  Candidate  Feature Pack for Communications Enabled Applications (CEA) before 1.0.0.1 for IBM WebSphere Application Server 7.0.0.7 uses predictable session values, which allows man-in-the-middle attackers to spoof a collaboration session by guessing the value.  Assigned (20090812)  None (candidate not yet proposed)    View
40440  CVE-2009-3005  Candidate  Lunascape 5.1.3 and 5.1.4 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page. NOTE: a related attack was reported in which an arbitrary file: URL is shown.  Assigned (20090828)  None (candidate not yet proposed)    View
40696  CVE-2009-3261  Candidate  update/update_0.1.2_to_0.2.php in LiveStreet 0.2 does not require administrative authentication, which allows remote attackers to perform DROP TABLE operations via unspecified vectors.  Assigned (20090918)  None (candidate not yet proposed)    View
40952  CVE-2009-3517  Candidate  nfs.ext in IBM AIX 5.3.x through 5.3.9 and 6.1.0 through 6.1.2 does not properly use the nfs_portmon setting, which allows remote attackers to bypass intended access restrictions for NFSv4 shares via unspecified vectors.  Assigned (20091001)  None (candidate not yet proposed)    View

Page 20348 of 20943, showing 5 records out of 104715 total, starting on record 101736, ending on 101740

Actions