NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48609  CVE-2009-1322  ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for database/aspProductCatalog.mdb.    Medium  2017-01-07  2009-04-17  View
48865  CVE-2009-1596  Ignite Realtime Openfire before 3.6.5 does not properly implement the register.password (aka canChangePassword) console configuration setting, which allows remote authenticated users to bypass intended policy and change their own passwords via a passwd_change IQ packet.    Medium  2017-01-07  2009-05-11  View
49121  CVE-2009-1855  Stack-based buffer overflow in Adobe Reader 7 and Acrobat 7 before 7.1.3, Adobe Reader 8 and Acrobat 8 before 8.1.6, and Adobe Reader 9 and Acrobat 9 before 9.1.2 might allow attackers to execute arbitrary code via a PDF file containing a malformed U3D model file with a crafted extension block.    9.3  High  2017-01-07  2010-05-04  View
49377  CVE-2009-2115  admin.php in SkyBlueCanvas 1.1 r237 allows remote authenticated administrators to obtain sensitive information via an invalid id parameter, which reveals the installation path in an error message.    6.8  Medium  2017-01-07  2009-06-22  View
49633  CVE-2009-2386  Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions allows remote attackers to force the download and execution of arbitrary files via the GetURL method.    9.3  High  2017-01-07  2009-07-13  View

Page 15620 of 17672, showing 5 records out of 88360 total, starting on record 78096, ending on 78100

Actions