NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48146 | CVE-2009-0831 | SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is disabled, allows remote authenticated users to execute arbitrary SQL commands via the sortby parameter. | 2 | 6 | Medium | 2017-01-07 | 2009-03-06 | View | |
48402 | CVE-2009-1092 | Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR systems allows remote attackers to execute arbitrary code by calling the GetAudioPlayingTime method with certain arguments. | 2 | 9.3 | High | 2017-01-07 | 2009-06-19 | View | |
48658 | CVE-2009-1373 | Buffer overflow in the XMPP SOCKS5 bytestream server in Pidgin (formerly Gaim) before 2.5.6 allows remote authenticated users to execute arbitrary code via vectors involving an outbound XMPP file transfer. NOTE: some of these details are obtained from third party information. | 2 | 7.1 | High | 2017-01-07 | 2013-11-02 | View | |
48914 | CVE-2009-1645 | Multiple stack-based buffer overflows in Mini-stream Easy RM-MP3 Converter 3.0.0.7 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file. | 2 | 9.3 | High | 2017-01-07 | 2009-05-15 | View | |
49170 | CVE-2009-1905 | The Common Code Infrastructure component in IBM DB2 8 before FP17, 9.1 before FP7, and 9.5 before FP4, when LDAP security (aka IBMLDAPauthserver) and anonymous bind are enabled, allows remote attackers to bypass password authentication and establish a database connection via unspecified vectors. | 2 | 2.6 | Low | 2017-01-07 | 2009-10-01 | View |
Page 1126 of 17672, showing 5 records out of 88360 total, starting on record 5626, ending on 5630