NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 51169 | CVE-2009-4016 | Integer underflow in the clean_string function in irc_string.c in (1) IRCD-hybrid 7.2.2 and 7.2.3, (2) ircd-ratbox before 2.2.9, and (3) oftc-hybrid before 1.6.8, when flatten_links is disabled, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a LINKS command. | 2 | 6.8 | Medium | 2017-01-07 | 2010-02-05 | View | |
| 51425 | CVE-2009-4302 | login/index_form.html in Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 links to an index page on the HTTP port even when the page is served from an HTTPS port, which might cause login credentials to be sent in cleartext, even when SSL is intended, and allows remote attackers to obtain these credentials by sniffing. | 2 | 5 | Medium | 2017-01-07 | 2009-12-16 | View | |
| 51681 | CVE-2009-4564 | SQL injection vulnerability in index.php in Zenphoto 1.2.5, when the ZenPage plugin is enabled, allows remote attackers to execute arbitrary SQL commands via the category parameter, related to a URI under news/category/. | 2 | 6.8 | Medium | 2017-01-07 | 2010-01-05 | View | |
| 51937 | CVE-2009-4820 | Angelo-Emlak 1.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for veribaze/angelo.mdb. | 2 | 5 | Medium | 2017-01-07 | 2010-04-28 | View | |
| 52193 | CVE-2009-5092 | Cross-site scripting (XSS) vulnerability in the management interface in Microsoft FAST ESP 5.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-07 | 2011-09-14 | View |
Page 15622 of 17672, showing 5 records out of 88360 total, starting on record 78106, ending on 78110