CVE List

Id CVE No. Status Description Phase Votes Comments Actions
41474  CVE-2009-4039  Candidate  Cross-site scripting (XSS) vulnerability in Piwigo before 2.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.  Assigned (20091120)  None (candidate not yet proposed)    View
41730  CVE-2009-4295  Candidate  Sun Ray Server Software 4.0 and 4.1 does not generate a unique DSA private key for the firmware on each Sun Ray 1, 1g, 100, and 150 DTU device, which makes it easier for remote attackers to obtain sensitive information by predicting a key and then using it to decrypt sniffed network traffic.  Assigned (20091211)  None (candidate not yet proposed)    View
41986  CVE-2009-4551  Candidate  SQL injection vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via the campaign_id parameter in a results action to index.php.  Assigned (20100104)  None (candidate not yet proposed)    View
42242  CVE-2009-4807  Candidate  Multiple SQL injection vulnerabilities in Graugon PHP Article Publisher 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) c parameter to index.php and the (2) id parameter to view.php.  Assigned (20100423)  None (candidate not yet proposed)    View
42498  CVE-2009-5063  Candidate  Memory leak in the embedded_profile_len function in pngwutil.c in libpng before 1.2.39beta5 allows context-dependent attackers to cause a denial of service (memory leak or segmentation fault) via a JPEG image containing an iCCP chunk with a negative embedded profile length. NOTE: this is due to an incomplete fix for CVE-2006-7244.  Assigned (20110328)  None (candidate not yet proposed)    View

Page 832 of 20943, showing 5 records out of 104715 total, starting on record 4156, ending on 4160

Actions