CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
41474 | CVE-2009-4039 | Candidate | Cross-site scripting (XSS) vulnerability in Piwigo before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Assigned (20091120) | None (candidate not yet proposed) | View | |
41730 | CVE-2009-4295 | Candidate | Sun Ray Server Software 4.0 and 4.1 does not generate a unique DSA private key for the firmware on each Sun Ray 1, 1g, 100, and 150 DTU device, which makes it easier for remote attackers to obtain sensitive information by predicting a key and then using it to decrypt sniffed network traffic. | Assigned (20091211) | None (candidate not yet proposed) | View | |
41986 | CVE-2009-4551 | Candidate | SQL injection vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a results action to index.php. | Assigned (20100104) | None (candidate not yet proposed) | View | |
42242 | CVE-2009-4807 | Candidate | Multiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) c parameter to index.php and the (2) id parameter to view.php. | Assigned (20100423) | None (candidate not yet proposed) | View | |
42498 | CVE-2009-5063 | Candidate | Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length. NOTE: this is due to an incomplete fix for CVE-2006-7244. | Assigned (20110328) | None (candidate not yet proposed) | View |
Page 832 of 20943, showing 5 records out of 104715 total, starting on record 4156, ending on 4160