NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 48859 | CVE-2009-1590 | Unspecified vulnerability in CGI RESCUE FORM2MAIL before 1.42 allows remote attackers to send email to arbitrary recipients via a web form. | 2 | 5 | Medium | 2017-01-07 | 2009-05-11 | View | |
| 48864 | CVE-2009-1595 | The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action. | 2 | 4 | Medium | 2017-01-07 | 2009-05-11 | View | |
| 48865 | CVE-2009-1596 | Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet. | 2 | 4 | Medium | 2017-01-07 | 2009-05-11 | View | |
| 5636 | CVE-2008-5905 | The web interface plugin in KTorrent before 3.1.4 allows remote attackers to bypass intended access restrictions and upload arbitrary torrent files, and trigger the start of downloads and seeding, via a crafted HTTP POST request. | 2 | 4.3 | Medium | 2017-01-03 | 2009-05-09 | View | |
| 5637 | CVE-2008-5906 | Eval injection vulnerability in the web interface plugin in KTorrent before 3.1.4 allows remote attackers to execute arbitrary PHP code via unspecified parameters to this interface"s PHP scripts. | 2 | 6.8 | Medium | 2017-01-03 | 2009-05-09 | View |
Page 14630 of 17672, showing 5 records out of 88360 total, starting on record 73146, ending on 73150