NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
47817  CVE-2009-0485  Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete unused flag types via a link or IMG tag to editflagtypes.cgi.    5.8  Medium  2017-01-07  2009-03-25  View
47818  CVE-2009-0486  Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.    7.5  High  2017-01-07  2009-03-25  View
48364  CVE-2009-1054  Unspecified vulnerability in JustSystems Ichitaro 13, 2004 through 2008, Lite2, and Ichitaro viewer 5.1.5.0 and earlier allows remote attackers to execute arbitrary code via a crafted file, as exploited in the wild by Trojan.Tarodrop.H in March 2009.    9.3  High  2017-01-07  2009-03-25  View
3834  CVE-2008-3972  pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card"s label matches the "OpenSC" string, which might allow physically proximate attackers to exploit vulnerabilities that the card owner expected were patched, as demonstrated by exploitation of CVE-2008-2235.    6.6  Medium  2017-01-03  2009-03-25  View
6238  CVE-2008-6507  Unspecified vulnerability in phpBB before 3.0.4 allows attackers to obtain sensitive information via unknown vectors related to the lack of password prompts for a private message that quotes a post in a password-protected forum.    Medium  2017-01-03  2009-03-24  View

Page 14784 of 17672, showing 5 records out of 88360 total, starting on record 73916, ending on 73920

Actions