NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
51221 | CVE-2009-4071 | Opera before 10.10, when exception stacktraces are enabled, places scripting error messages from a web site into variables that can be read by a different web site, which allows remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via unspecified vectors. | 2 | 5.8 | Medium | 2017-01-07 | 2010-08-21 | View | |
51477 | CVE-2009-4354 | TransWARE Active! mail 2003 build 2003.0139.0871 and earlier does not properly secure the session ID in a session cookie, which allows remote attackers to hijack web sessions, probably related to the "secure" flag for cookies in SSL sessions. | 2 | 5.8 | Medium | 2017-01-07 | 2009-12-21 | View | |
51733 | CVE-2009-4616 | Cross-site scripting (XSS) vulnerability in search.php in MYRE Holiday Rental Manager allows remote attackers to inject arbitrary web script or HTML via the cat_id1 parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2011-04-29 | View | |
51989 | CVE-2009-4872 | Multiple SQL injection vulnerabilities in globepersonnel_login.asp in Logoshows BBS 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) username and (2) password fields. | 2 | 7.5 | High | 2017-01-07 | 2010-05-11 | View | |
52245 | CVE-2007-0008 | Integer underflow in the SSLv2 support in Mozilla Network Security Services (NSS) before 3.11.5, as used by Firefox before 1.5.0.10 and 2.x before 2.0.0.2, SeaMonkey before 1.0.8, Thunderbird before 1.5.0.10, and certain Sun Java System server products before 20070611, allows remote attackers to execute arbitrary code via a crafted SSLv2 server message containing a public key that is too short to encrypt the "Master Secret", which results in a heap-based overflow. | 2 | 6.8 | Medium | 2017-01-07 | 2014-05-04 | View |
Page 1307 of 17672, showing 5 records out of 88360 total, starting on record 6531, ending on 6535