NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 48609 | CVE-2009-1322 | ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for database/aspProductCatalog.mdb. | 2 | 5 | Medium | 2017-01-07 | 2009-04-17 | View | |
| 48865 | CVE-2009-1596 | Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet. | 2 | 4 | Medium | 2017-01-07 | 2009-05-11 | View | |
| 49121 | CVE-2009-1855 | Stack-based buffer overflow in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attackers to execute arbitrary code via a PDF file containing a malformed U3D model file with a crafted extension block. | 2 | 9.3 | High | 2017-01-07 | 2010-05-04 | View | |
| 49377 | CVE-2009-2115 | admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to obtain sensitive information via an invalid id parameter, which reveals the installation path in an error message. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-22 | View | |
| 49633 | CVE-2009-2386 | Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method. | 2 | 9.3 | High | 2017-01-07 | 2009-07-13 | View |
Page 15620 of 17672, showing 5 records out of 88360 total, starting on record 78096, ending on 78100