CVE List

Id CVE No. Status Description Phase Votes Comments Actions
38405  CVE-2009-0970  Candidate  PHP remote file inclusion vulnerability in includes/class_image.php in PHP Pro Bid 6.05, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the fileExtension parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20090318)  None (candidate not yet proposed)    View
103941  CVE-2017-7121  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170317)  None (candidate not yet proposed)    View
38661  CVE-2009-1226  Candidate  core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.  Assigned (20090402)  None (candidate not yet proposed)    View
104197  CVE-2017-7377  Candidate  The (1) v9fs_create and (2) v9fs_lcreate functions in hw/9pfs/9p.c in QEMU (aka Quick Emulator) allow local guest OS privileged users to cause a denial of service (file descriptor or memory consumption) via vectors related to an already in-use fid.  Assigned (20170331)  None (candidate not yet proposed)    View
38917  CVE-2009-1482  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in action/AttachFile.py in MoinMoin 1.8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) an AttachFile sub-action in the error_msg function or (2) multiple vectors related to package file errors in the upload_form function, different vectors than CVE-2009-0260.  Assigned (20090429)  None (candidate not yet proposed)    View

Page 458 of 20943, showing 5 records out of 104715 total, starting on record 2286, ending on 2290

Actions