NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48915 | CVE-2009-1646 | Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a long rtsp URL in a .ram file. | 2 | 9.3 | High | 2017-01-07 | 2009-05-15 | View | |
49171 | CVE-2009-1906 | The DRDA Services component in IBM DB2 9.1 before FP7 and 9.5 before FP4 allows remote attackers to cause a denial of service (memory corruption and application crash) via an IPv6 address in the correlation token in the APPID string, as demonstrated by an APPID string sent by the third-party DataDirect JDBC driver 3.7.32. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-10 | View | |
49427 | CVE-2009-2165 | SerendipityNZ (aka SimpleBoxes) Serene Bach 2.20R and earlier, and 3.00 beta023 and earlier 3.x versions, uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a modified id. | 2 | 7.5 | High | 2017-01-07 | 2009-06-26 | View | |
49683 | CVE-2009-2438 | Cross-site scripting (XSS) vulnerability in index.php in the search module in ClanSphere 2009.0 and 2009.0.2 allows remote attackers to inject arbitrary web script or HTML via the text parameter in a list action. NOTE: this might overlap CVE-2008-1399. | 2 | 4.3 | Medium | 2017-01-07 | 2009-07-13 | View | |
49939 | CVE-2009-2698 | The udp_sendmsg function in the UDP implementation in (1) net/ipv4/udp.c and (2) net/ipv6/udp.c in the Linux kernel before 2.6.19 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving the MSG_MORE flag and a UDP socket. | 2 | 7.2 | High | 2017-01-07 | 2012-03-19 | View |
Page 1186 of 17672, showing 5 records out of 88360 total, starting on record 5926, ending on 5930