NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
49172 | CVE-2009-1907 | Cross-site scripting (XSS) vulnerability in claroline/linker/notfound.php in Claroline 1.8.11 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-05 | View | |
49428 | CVE-2009-2166 | Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to read arbitrary files via a full pathname in the log parameter. | 2 | 5 | Medium | 2017-01-07 | 2009-06-23 | View | |
49684 | CVE-2009-2439 | Multiple SQL injection vulnerabilities in Web Development House Alibaba Clone allow remote attackers to execute arbitrary SQL commands via the (1) IndustryID parameter to category.php and the (2) SellerID parameter to supplier/view_contact_details.php. NOTE: this is a product that was developed by a third party; it is not associated with alibaba.com or the Alibaba Group. | 2 | 7.5 | High | 2017-01-07 | 2010-02-13 | View | |
49940 | CVE-2009-2699 | The Solaris pollset feature in the Event Port backend in poll/unix/port.c in the Apache Portable Runtime (APR) library before 1.3.9, as used in the Apache HTTP Server before 2.2.14 and other products, does not properly handle errors, which allows remote attackers to cause a denial of service (daemon hang) via unspecified HTTP requests, related to the prefork and event MPMs. | 2 | 5 | Medium | 2017-01-07 | 2016-08-22 | View | |
50196 | CVE-2009-2979 | Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 do not properly perform XMP-XML entity expansion, which allows remote attackers to cause a denial of service via a crafted document. | 2 | 4.3 | Medium | 2017-01-07 | 2010-08-21 | View |
Page 1414 of 17672, showing 5 records out of 88360 total, starting on record 7066, ending on 7070