CVE List

Id CVE No. Status Description Phase Votes Comments Actions
40201  CVE-2009-2766  Candidate  httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs under cgi-bin/, which allows remote attackers to change settings via HTTP requests.  Assigned (20090814)  None (candidate not yet proposed)    View
40457  CVE-2009-3022  Candidate  Cross-site request forgery (CSRF) vulnerability in bingo!CMS 1.2 and earlier allows remote attackers to hijack the authentication of other users for requests that modify configuration or change content via unspecified vectors.  Assigned (20090831)  None (candidate not yet proposed)    View
40713  CVE-2009-3278  Candidate  The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery key, which makes it easier for local users to determine this key via a brute-force attack.  Assigned (20090921)  None (candidate not yet proposed)    View
40969  CVE-2009-3534  Candidate  Directory traversal vulnerability in index.php in LionWiki 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter.  Assigned (20091002)  None (candidate not yet proposed)    View
41225  CVE-2009-3790  Candidate  Heap-based buffer overflow in FormMax (formerly AcroForm) evaluation 3.5 allows remote attackers to cause a denial of service or possibly execute arbitrary code via a crafted FormMax import (.aim) file. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.  Assigned (20091026)  None (candidate not yet proposed)    View

Page 787 of 20943, showing 5 records out of 104715 total, starting on record 3931, ending on 3935

Actions