NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48142  CVE-2009-0827  PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request.    Medium  2017-01-07  2009-03-06  View
48398  CVE-2009-1088  Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Java code via a crafted XSLT stylesheet with "extension elements and extension functions" that trigger code execution by Xalan-Java, as demonstrated using xalan://java.lang.Runtime.    High  2017-01-07  2009-10-05  View
48654  CVE-2009-1369  moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) page[] and (3) cat[] parameter to index.php, or (4) file[] parameter to download.php, which reveals the installation path in an error message.    Medium  2017-01-07  2009-04-23  View
48910  CVE-2009-1641  Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via (1) a long rtsp URL in a .ram file and (2) a long string in the HREF attribute of a REF element in a .asx file.    9.3  High  2017-01-07  2009-05-15  View
49166  CVE-2009-1901  The Security component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35 permits "non-standard http methods," which has unknown impact and remote attack vectors.    10  High  2017-01-07  2009-06-24  View

Page 1357 of 17672, showing 5 records out of 88360 total, starting on record 6781, ending on 6785

Actions