CVE List

Id CVE No. Status Description Phase Votes Comments Actions
39176  CVE-2009-1741  Candidate  Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.  Assigned (20090520)  None (candidate not yet proposed)    View
104712  CVE-2017-7892  Candidate  Sandstorm Cap"n Proto before 0.5.3.1 allows remote crashes related to a compiler optimization. A remote attacker can trigger a segfault in a 32-bit libcapnp application because Cap"n Proto relies on pointer arithmetic calculations that overflow. An example compiler with optimization that elides a bounds check in such calculations is Apple LLVM version 8.1.0 (clang-802.0.41). The attack vector is a crafted far pointer within a message.  Assigned (20170417)  None (candidate not yet proposed)    View
39432  CVE-2009-1997  Candidate  Unspecified vulnerability in the Authentication component in Oracle Database 10.2.0.3 and 11.1.0.7 allows remote attackers to affect confidentiality via unknown vectors.  Assigned (20090608)  None (candidate not yet proposed)    View
39688  CVE-2009-2253  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20090627)  None (candidate not yet proposed)    View
39944  CVE-2009-2509  Candidate  Active Directory Federation Services (ADFS) in Microsoft Windows Server 2003 SP2 and Server 2008 Gold and SP2 does not properly validate headers in HTTP requests, which allows remote authenticated users to execute arbitrary code via a crafted request to an IIS web server, aka "Remote Code Execution in ADFS Vulnerability."  Assigned (20090717)  None (candidate not yet proposed)    View

Page 705 of 20943, showing 5 records out of 104715 total, starting on record 3521, ending on 3525

Actions