48899 |
CVE-2009-1630 |
The nfs_permission function in fs/nfs/dir.c in the NFS client implementation in the Linux kernel 2.6.29.3 and earlier, when atomic_open is available, does not check execute (aka EXEC or MAY_EXEC) permission bits, which allows local users to bypass permissions and execute files, as demonstrated by files on an NFSv4 fileserver. |
|
2 |
4.4 |
Medium |
2017-01-07 |
2012-04-12 |
View
|
49411 |
CVE-2009-2149 |
Multiple cross-site scripting (XSS) vulnerabilities in Campus Virtual-LMS allow remote attackers to inject arbitrary web script or HTML via the (1) courseid parameter to enrolments/step1.php, or the (2) search or (3) siteid parameter to files/shared_list.php. |
|
2 |
4.3 |
Medium |
2017-01-07 |
2009-06-23 |
View
|
50435 |
CVE-2009-3230 |
The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7.4.26 does not use the appropriate privileges for the (1) RESET ROLE and (2) RESET SESSION AUTHORIZATION operations, which allows remote authenticated users to gain privileges. NOTE: this is due to an incomplete fix for CVE-2007-6600. |
|
2 |
6.5 |
Medium |
2017-01-07 |
2016-08-22 |
View
|
50691 |
CVE-2009-3490 |
GNU Wget before 1.12 does not properly handle a " |