CVE List

Id CVE No. Status Description Phase Votes Comments Actions
42250  CVE-2009-4815  Candidate  Directory traversal vulnerability in Serv-U before 9.2.0.1 allows remote authenticated users to read arbitrary files via unspecified vectors.  Assigned (20100427)  None (candidate not yet proposed)    View
42506  CVE-2009-5071  Candidate  Unspecified vulnerability in Palm Pre WebOS before 1.2.1 has unknown impact and attack vectors related to an "included contact template file."  Assigned (20110419)  None (candidate not yet proposed)    View
42762  CVE-2010-0178  Candidate  Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2, and SeaMonkey before 2.0.4, does not prevent applets from interpreting mouse clicks as drag-and-drop actions, which allows remote attackers to execute arbitrary JavaScript with Chrome privileges by loading a chrome: URL and then loading a javascript: URL.  Assigned (20100106)  None (candidate not yet proposed)    View
43018  CVE-2010-0434  Candidate  The ap_read_request function in server/protocol.c in the Apache HTTP Server 2.2.x before 2.2.15, when a multithreaded MPM is used, does not properly handle headers in subrequests in certain circumstances involving a parent request that has a body, which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.  Assigned (20100127)  None (candidate not yet proposed)    View
43274  CVE-2010-0690  Candidate  SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbitrary SQL commands via the pfid parameter in a catalog action.  Assigned (20100223)  None (candidate not yet proposed)    View

Page 868 of 20943, showing 5 records out of 104715 total, starting on record 4336, ending on 4340

Actions