NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48082  CVE-2009-0763  Cross-site scripting (XSS) vulnerability in default.php in Kipper 2.01 allows remote attackers to inject arbitrary web script or HTML via the charm parameter.    4.3  Medium  2017-01-07  2009-06-17  View
48338  CVE-2009-1028  Stack-based buffer overflow in ediSys eZip Wizard 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file.    9.3  High  2017-01-07  2011-09-21  View
48594  CVE-2009-1307  The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI.    6.8  Medium  2017-01-07  2010-08-21  View
48850  CVE-2009-1581  functions/mime.php in SquirrelMail before 1.4.18 does not protect the application"s content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message.    4.3  Medium  2017-01-07  2010-08-21  View
49106  CVE-2009-1840  Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page.    9.3  High  2017-01-07  2010-08-21  View

Page 14595 of 17672, showing 5 records out of 88360 total, starting on record 72971, ending on 72975

Actions