CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
41475 | CVE-2009-4040 | Candidate | Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the search page. | Assigned (20091120) | None (candidate not yet proposed) | View | |
41731 | CVE-2009-4296 | Candidate | SQL injection vulnerability in the Taxonomy Timer module 5.x-1.8 and earlier and 6.x-alpha1 and earlier for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Assigned (20091211) | None (candidate not yet proposed) | View | |
41987 | CVE-2009-4552 | Candidate | Cross-site scripting (XSS) vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to index.php. | Assigned (20100104) | None (candidate not yet proposed) | View | |
42243 | CVE-2009-4808 | Candidate | admin.php in Graugon PHP Article Publisher 1.0 allows remote attackers to bypass authentication and obtain administrative access by setting the g_admin cookie to 1. | Assigned (20100423) | None (candidate not yet proposed) | View | |
42499 | CVE-2009-5064 | Candidate | ** DISPUTED ** ldd in the GNU C Library (aka glibc or libc6) 2.13 and earlier allows local users to gain privileges via a Trojan horse executable file linked with a modified loader that omits certain LD_TRACE_LOADED_OBJECTS checks. NOTE: the GNU C Library vendor states "This is just nonsense. There are a gazillion other ways to introduce code if people are downloading arbitrary binaries and install them in appropriate directories or set LD_LIBRARY_PATH etc." | Assigned (20110330) | None (candidate not yet proposed) | View |
Page 328 of 20943, showing 5 records out of 104715 total, starting on record 1636, ending on 1640