CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41980  CVE-2009-4545  Candidate  Logoshows BBS 2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for database/globepersonnel.mdb.  Assigned (20100104)  None (candidate not yet proposed)    View
42236  CVE-2009-4801  Candidate  EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via requests to PHP scripts.  Assigned (20100423)  None (candidate not yet proposed)    View
42492  CVE-2009-5057  Candidate  The S/MIME feature in Open Ticket Request System (OTRS) before 2.3.4 does not configure the RANDFILE and HOME environment variables for OpenSSL, which might make it easier for remote attackers to decrypt e-mail messages that had lower than intended entropy available for cryptographic operations, related to inability to write to the seeding file.  Assigned (20110318)  None (candidate not yet proposed)    View
42748  CVE-2010-0164  Candidate  Use-after-free vulnerability in the imgContainer::InternalAddFrameHelper function in src/imgContainer.cpp in libpr0n in Mozilla Firefox 3.6 before 3.6.2 allows remote attackers to cause a denial of service (heap memory corruption and application crash) or possibly execute arbitrary code via a multipart/x-mixed-replace animation in which the frames have different bits-per-pixel (bpp) values.  Assigned (20100106)  None (candidate not yet proposed)    View
43004  CVE-2010-0420  Candidate  libpurple in Finch in Pidgin before 2.6.6, when an XMPP multi-user chat (MUC) room is used, does not properly parse nicknames containing <br> sequences, which allows remote attackers to cause a denial of service (application crash) via a crafted nickname.  Assigned (20100127)  None (candidate not yet proposed)    View

Page 20687 of 20943, showing 5 records out of 104715 total, starting on record 103431, ending on 103435

Actions