NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48162 | CVE-2009-0847 | The asn1buf_imbed function in the ASN.1 decoder in MIT Kerberos 5 (aka krb5) 1.6.3, when PK-INIT is used, allows remote attackers to cause a denial of service (application crash) via a crafted length value that triggers an erroneous malloc call, related to incorrect calculations with pointer arithmetic. | 2 | 4.3 | Medium | 2017-01-07 | 2010-08-21 | View | |
48930 | CVE-2009-1661 | SQL injection vulnerability in admin/utopic.php in uTopic 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the rating parameter to index.php. | 2 | 6.8 | Medium | 2017-01-07 | 2009-05-19 | View | |
49186 | CVE-2009-1922 | The Message Queuing (aka MSMQ) service for Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP2, and Vista Gold does not properly validate unspecified IOCTL request data from user mode before passing this data to kernel mode, which allows local users to gain privileges via a crafted request, aka "MSMQ Null Pointer Vulnerability." | 2 | 6.9 | Medium | 2017-01-07 | 2010-08-21 | View | |
49442 | CVE-2009-2180 | Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) absolute path in the file parameter. | 2 | 5 | Medium | 2017-01-07 | 2013-08-07 | View | |
49954 | CVE-2009-2717 | The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on Windows 2000 Professional does not provide a Security Warning Icon, which makes it easier for context-dependent attackers to trick a user into interacting unsafely with an untrusted applet. | 2 | 6.8 | Medium | 2017-01-07 | 2009-08-11 | View |
Page 1263 of 17672, showing 5 records out of 88360 total, starting on record 6311, ending on 6315