NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49646 | CVE-2009-2399 | PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-07-09 | View | |
| 49902 | CVE-2009-2661 | The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data. NOTE: this is due to an incomplete fix for CVE-2009-2185. | 2 | 5 | Medium | 2017-01-07 | 2009-11-24 | View | |
| 50158 | CVE-2009-2937 | Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed. | 2 | 4.3 | Medium | 2017-01-07 | 2009-09-18 | View | |
| 50414 | CVE-2009-3209 | SQL injection vulnerability in remove.php in PHP eMail Manager 3.3.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-09-17 | View | |
| 50670 | CVE-2009-3469 | Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-10-03 | View |
Page 14431 of 17672, showing 5 records out of 88360 total, starting on record 72151, ending on 72155