NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49080 | CVE-2009-1814 | SQL injection vulnerability in mail.php in PHPenpals 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. NOTE: the profile.php vector is already covered by CVE-2006-0074. | 2 | 7.5 | High | 2017-01-07 | 2009-06-01 | View | |
| 49592 | CVE-2009-2344 | The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authenticated users to gain privileges via a $admin value for the admin parameter in an edit action to admin/user/user.cgi and unspecified other components. | 2 | 9 | High | 2017-01-07 | 2009-07-08 | View | |
| 50616 | CVE-2009-3415 | Unspecified vulnerability in the Oracle OLAP component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors. | 2 | 9 | High | 2017-01-07 | 2012-10-22 | View | |
| 50872 | CVE-2009-3674 | Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly initialized or (2) is deleted, leading to memory corruption, aka "Uninitialized Memory Corruption Vulnerability," a different vulnerability than CVE-2009-3671. | 2 | 9.3 | High | 2017-01-07 | 2010-08-21 | View | |
| 51128 | CVE-2009-3969 | Stack-based buffer overflow in Faslo Player 7.0 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a .m3u playlist file. | 2 | 9.3 | High | 2017-01-07 | 2009-11-19 | View |
Page 15366 of 17672, showing 5 records out of 88360 total, starting on record 76826, ending on 76830