CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
40711 | CVE-2009-3276 | Candidate | Zoran/WinFormsAdvansed/RegeularDataToXML/Form1.cs in WinFormsAdvansed in NASD CORE.NET Terelik (aka corenet1) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many alphabetic characters followed by a ! (exclamation point), related to a certain regular expression, aka a "ReDoS" vulnerability. | Assigned (20090921) | None (candidate not yet proposed) | View | |
40967 | CVE-2009-3532 | Candidate | Multiple SQL injection vulnerabilities in login.asp (aka the login screen) in LogRover 2.3 and 2.3.3 on Windows allow remote attackers to execute arbitrary SQL commands via the (1) uname and (2) pword parameters. NOTE: some of these details are obtained from third party information. | Assigned (20091002) | None (candidate not yet proposed) | View | |
41223 | CVE-2009-3788 | Candidate | SQL injection vulnerability in index.php in OpenDocMan 1.2.5 allows remote attackers to execute arbitrary SQL commands via the frmuser (aka Username) parameter. | Assigned (20091026) | None (candidate not yet proposed) | View | |
41479 | CVE-2009-4044 | Candidate | The Web Services module 6.x for Drupal does not perform the expected access control, which allows remote attackers to make unspecified use of an API via unknown vectors. | Assigned (20091120) | None (candidate not yet proposed) | View | |
41735 | CVE-2009-4300 | Candidate | Multiple unspecified authentication plugins in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 store the MD5 hashes for passwords in the user table, even when the cached hashes are not used by the plugin, which might make it easier for attackers to obtain credentials via unspecified vectors. | Assigned (20091211) | None (candidate not yet proposed) | View |
Page 621 of 20943, showing 5 records out of 104715 total, starting on record 3101, ending on 3105