CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41475  CVE-2009-4040  Candidate  Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the search page.  Assigned (20091120)  None (candidate not yet proposed)    View
41731  CVE-2009-4296  Candidate  SQL injection vulnerability in the Taxonomy Timer module 5.x-1.8 and earlier and 6.x-alpha1 and earlier for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.  Assigned (20091211)  None (candidate not yet proposed)    View
41987  CVE-2009-4552  Candidate  Cross-site scripting (XSS) vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php.  Assigned (20100104)  None (candidate not yet proposed)    View
42243  CVE-2009-4808  Candidate  admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the g_admin cookie to 1.  Assigned (20100423)  None (candidate not yet proposed)    View
42499  CVE-2009-5064  Candidate  ** DISPUTED ** ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a modified loader that omits certain LD_TRACE_LOADED_OBJECTS checks. NOTE: the GNU C Library vendor states "This is just nonsense. There are a gazillion other ways to introduce code if people are downloading arbitrary binaries and install them in appropriate directories or set LD_LIBRARY_PATH etc."  Assigned (20110330)  None (candidate not yet proposed)    View

Page 328 of 20943, showing 5 records out of 104715 total, starting on record 1636, ending on 1640

Actions