NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48859  CVE-2009-1590  Unspecified vulnerability in CGI RESCUE FORM2MAIL before 1.42 allows remote attackers to send email to arbitrary recipients via a web form.    Medium  2017-01-07  2009-05-11  View
48864  CVE-2009-1595  The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action.    Medium  2017-01-07  2009-05-11  View
48865  CVE-2009-1596  Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.    Medium  2017-01-07  2009-05-11  View
5636  CVE-2008-5905  The web interface plugin in KTorrent before 3.1.4 allows remote attackers to bypass intended access restrictions and upload arbitrary torrent files, and trigger the start of downloads and seeding, via a crafted HTTP POST request.    4.3  Medium  2017-01-03  2009-05-09  View
5637  CVE-2008-5906  Eval injection vulnerability in the web interface plugin in KTorrent before 3.1.4 allows remote attackers to execute arbitrary PHP code via unspecified parameters to this interface"s PHP scripts.    6.8  Medium  2017-01-03  2009-05-09  View

Page 14630 of 17672, showing 5 records out of 88360 total, starting on record 73146, ending on 73150

Actions