NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 48594 | CVE-2009-1307 | The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI. | 2 | 6.8 | Medium | 2017-01-07 | 2010-08-21 | View | |
| 48850 | CVE-2009-1581 | functions/mime.php in SquirrelMail before 1.4.18 does not protect the application"s content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message. | 2 | 4.3 | Medium | 2017-01-07 | 2010-08-21 | View | |
| 49106 | CVE-2009-1840 | Mozilla Firefox before 3.0.11, Thunderbird, and SeaMonkey do not check content policy before loading a script file into a XUL document, which allows remote attackers to bypass intended access restrictions via a crafted HTML document, as demonstrated by a "web bug" in an e-mail message, or web script or an advertisement in a web page. | 2 | 9.3 | High | 2017-01-07 | 2010-08-21 | View | |
| 49362 | CVE-2009-2100 | Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php. | 2 | 5 | Medium | 2017-01-07 | 2009-10-08 | View | |
| 49618 | CVE-2009-2371 | Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature. | 2 | 6.5 | Medium | 2017-01-07 | 2009-07-08 | View |
Page 14931 of 17672, showing 5 records out of 88360 total, starting on record 74651, ending on 74655