NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48409 | CVE-2009-1099 | Integer signedness error in Java SE Development Kit (JDK) and Java Runtime Environment (JRE) 5.0 Update 17 and earlier, and 6 Update 12 and earlier, allows remote attackers to access files or execute arbitrary code via crafted glyph descriptions in a Type1 font, which bypasses a signed comparison and triggers a buffer overflow. | 2 | 7.5 | High | 2017-01-07 | 2012-10-22 | View | |
48665 | CVE-2009-1380 | Cross-site scripting (XSS) vulnerability in JMX-Console in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 allows remote attackers to inject arbitrary web script or HTML via the filter parameter, related to the key property and the position of quote and colon characters. | 2 | 4.3 | Medium | 2017-01-07 | 2009-12-16 | View | |
48921 | CVE-2009-1652 | admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attackers to gain privileges and add administrators via a direct request. | 2 | 7.5 | High | 2017-01-07 | 2009-05-23 | View | |
49177 | CVE-2009-1912 | Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-05 | View | |
49433 | CVE-2009-2171 | Mahara 1.1 before 1.1.5 does not apply permission checks when saving a view that contains artefacts, which allows remote authenticated users to read another user"s artefact. | 2 | 4 | Medium | 2017-01-07 | 2009-06-24 | View |
Page 1547 of 17672, showing 5 records out of 88360 total, starting on record 7731, ending on 7735