NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 48009 | CVE-2009-0686 | The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows local users to gain privileges via a crafted IRP in a METHOD_NEITHER IOCTL request to Device mactmon that overwrites memory. | 2 | 7.2 | High | 2017-01-07 | 2009-04-10 | View | |
| 47534 | CVE-2009-0197 | Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large XPM file that triggers a heap-based buffer overflow. | 2 | 9.3 | High | 2017-01-07 | 2009-04-10 | View | |
| 48568 | CVE-2009-1281 | Cross-site scripting (XSS) vulnerability in glFusion before 1.1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-07 | 2009-04-10 | View | |
| 48570 | CVE-2009-1283 | glFusion before 1.1.3 performs authentication with a user-provided password hash instead of a password, which allows remote attackers to gain privileges by obtaining the hash and using it in the glf_password cookie, aka "User Masquerading." NOTE: this can be leveraged with a separate SQL injection vulnerability to steal hashes. | 2 | 6.8 | Medium | 2017-01-07 | 2009-04-10 | View | |
| 47593 | CVE-2009-0259 | The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted (1) .doc, (2) .wri, or (3) .rtf Word 97 file that triggers memory corruption, as exploited in the wild in December 2008, as demonstrated by 2008-crash.doc.rar, and a similar issue to CVE-2008-4841. | 2 | 9.3 | High | 2017-01-07 | 2009-04-10 | View |
Page 14709 of 17672, showing 5 records out of 88360 total, starting on record 73541, ending on 73545