NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49049  CVE-2009-1780  admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, which allows remote attackers to gain administrative privileges via modified form_admin_user and form_admin_pass parameters.    7.5  High  2017-01-07  2009-05-27  View
49561  CVE-2009-2313  Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the name parameter.    7.5  High  2017-01-07  2009-07-02  View
50329  CVE-2009-3114  The RSS reader widget in IBM Lotus Notes 8.0 and 8.5 saves items from an RSS feed as local HTML documents, which allows remote attackers to execute arbitrary script in Internet Explorer"s Local Machine Zone via a crafted feed, aka SPR RGAU7RDJ9K.    7.5  High  2017-01-07  2009-10-01  View
50585  CVE-2009-3381  Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.    10  High  2017-01-07  2010-08-21  View
51865  CVE-2009-4748  SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the parentID parameter in an act_OrderCategories action to wp-admin/post-new.php.    7.5  High  2017-01-07  2010-03-29  View

Page 14524 of 17672, showing 5 records out of 88360 total, starting on record 72616, ending on 72620

Actions