CVE List

Id CVE No. Status Description Phase Votes Comments Actions
37887  CVE-2009-0452  Candidate  Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) uname or (2) pass parameter.  Assigned (20090205)  None (candidate not yet proposed)    View
103423  CVE-2017-6603  Candidate  A vulnerability in Cisco ASR 903 or ASR 920 Series Devices running with an RSP2 card could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on a targeted system because of incorrect IPv6 Packet Processing. More Information: CSCuy94366. Known Affected Releases: 15.4(3)S3.15. Known Fixed Releases: 15.6(2)SP 15.6(1.31)SP.  Assigned (20170309)  None (candidate not yet proposed)    View
38143  CVE-2009-0708  Candidate  Multiple cross-site request forgery (CSRF) vulnerabilities in SemanticScuttle before 0.91 allow remote attackers to (1) hijack the authentication of administrators via unknown vectors or (2) hijack the authentication of arbitrary users via vectors involving the profile page.  Assigned (20090223)  None (candidate not yet proposed)    View
103679  CVE-2017-6859  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170313)  None (candidate not yet proposed)    View
38399  CVE-2009-0964  Candidate  UserView_list.php in PHPRunner 4.2, and possibly earlier, stores passwords in cleartext in the database, which allows attackers to gain privileges. NOTE: this can be leveraged with a separate SQL injection vulnerability to obtain passwords remotely without authentication.  Assigned (20090318)  None (candidate not yet proposed)    View

Page 20921 of 20943, showing 5 records out of 104715 total, starting on record 104601, ending on 104605

Actions