NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49614  CVE-2009-2367  cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter.    7.5  High  2017-01-07  2009-07-08  View
49615  CVE-2009-2368  Unspecified vulnerability in Socks Server 5 before 3.7.8-8 has unknown impact and attack vectors.    10  High  2017-01-07  2009-07-08  View
49617  CVE-2009-2370  Cross-site scripting (XSS) vulnerability in Advanced Forum 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.    4.3  Medium  2017-01-07  2009-07-08  View
49618  CVE-2009-2371  Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.    6.5  Medium  2017-01-07  2009-07-08  View
49619  CVE-2009-2372  Drupal 6.x before 6.13 does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.    6.5  Medium  2017-01-07  2009-07-08  View

Page 14473 of 17672, showing 5 records out of 88360 total, starting on record 72361, ending on 72365

Actions