CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40711  CVE-2009-3276  Candidate  Zoran/WinFormsAdvansed/RegeularDataToXML/Form1.cs in WinFormsAdvansed in NASD CORE.NET Terelik (aka corenet1) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many alphabetic characters followed by a ! (exclamation point), related to a certain regular expression, aka a "ReDoS" vulnerability.  Assigned (20090921)  None (candidate not yet proposed)    View
40967  CVE-2009-3532  Candidate  Multiple SQL injection vulnerabilities in login.asp (aka the login screen) in LogRover 2.3 and 2.3.3 on Windows allow remote attackers to execute arbitrary SQL commands via the (1) uname and (2) pword parameters. NOTE: some of these details are obtained from third party information.  Assigned (20091002)  None (candidate not yet proposed)    View
41223  CVE-2009-3788  Candidate  SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmuser (aka Username) parameter.  Assigned (20091026)  None (candidate not yet proposed)    View
41479  CVE-2009-4044  Candidate  The Web Services module 6.x for Drupal does not perform the expected access control, which allows remote attackers to make unspecified use of an API via unknown vectors.  Assigned (20091120)  None (candidate not yet proposed)    View
41735  CVE-2009-4300  Candidate  Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, even when the cached hashes are not used by the plugin, which might make it easier for attackers to obtain credentials via unspecified vectors.  Assigned (20091211)  None (candidate not yet proposed)    View

Page 621 of 20943, showing 5 records out of 104715 total, starting on record 3101, ending on 3105

Actions