CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40712  CVE-2009-3277  Candidate  DataVault.Tesla/Impl/TypeSystem/AssociationHelper.cs in datavault allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of an [ (open bracket) followed by many commas, related to a certain regular expression, aka a "ReDoS" vulnerability.  Assigned (20090921)  None (candidate not yet proposed)    View
40968  CVE-2009-3533  Candidate  SQL injection vulnerability in report.php in Meeting Room Booking System (MRBS) before 1.4.2 allows remote attackers to execute arbitrary SQL commands via the typematch parameter. NOTE: some of these details are obtained from third party information.  Assigned (20091002)  None (candidate not yet proposed)    View
41224  CVE-2009-3789  Candidate  Multiple cross-site scripting (XSS) vulnerabilities in OpenDocMan 1.2.5 allow remote attackers to inject arbitrary web script or HTML via the last_message parameter to (1) add.php, (2) toBePublished.php, (3) index.php, and (4) admin.php; the PATH_INFO to the default URI to (5) category.php, (6) department.php, (7) profile.php, (8) rejects.php, (9) search.php, (10) toBePublished.php, (11) user.php, and (12) view_file.php; and (13) the caller parameter in a Modify User action to user.php.  Assigned (20091026)  None (candidate not yet proposed)    View
41480  CVE-2009-4045  Candidate  Multiple SQL injection vulnerabilities in FrontAccounting (FA) before 2.1.7 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to various .inc and .php files in (1) reporting/, (2) sales/, (3) sales/includes/, (4) sales/includes/db/, (5) sales/inquiry/, (6) sales/manage/, (7) sales/view/, (8) taxes/, and (9) taxes/db/.  Assigned (20091120)  None (candidate not yet proposed)    View
41736  CVE-2009-4301  Candidate  mnet/lib.php in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7, when MNET services are enabled, does not properly check permissions, which allows remote authenticated servers to execute arbitrary MNET functions.  Assigned (20091211)  None (candidate not yet proposed)    View

Page 713 of 20943, showing 5 records out of 104715 total, starting on record 3561, ending on 3565

Actions