| 48380 |
CVE-2009-1070 |
Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter. |
|
2 |
4.3 |
Medium |
2017-01-07 |
2009-03-27 |
View
|
| 48381 |
CVE-2009-1071 |
Stack-based buffer overflow in Icarus 2.0 allows remote attackers to cause a denial of service (application crach) or execute arbitrary code via a crafted Portable Game Notation (.pgn) file. |
|
2 |
9.3 |
High |
2017-01-07 |
2009-03-27 |
View
|
| 4 |
CVE-2008-0004 |
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. |
1 |
|
|
|
2017-01-03 |
2009-03-26 |
View
|
| 5638 |
CVE-2008-5907 |
The png_check_keyword function in pngwutil.c in libpng before 1.0.42, and 1.2.x before 1.2.34, might allow context-dependent attackers to set the value of an arbitrary memory location to zero via vectors involving creation of crafted PNG files with keywords, related to an implicit cast of the " |