NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
50403  CVE-2009-3198  Cross-site scripting (XSS) vulnerability in search.php in JCE-Tech Affiliate Master Datafeed Parser Script 2.0 allows remote attackers to inject arbitrary web script or HTML via the search parameter.    4.3  Medium  2017-01-07  2009-09-16  View
50659  CVE-2009-3458  Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 do not properly validate input, which might allow attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2009-2998.    9.3  High  2017-01-07  2010-08-21  View
50915  CVE-2009-3732  Format string vulnerability in vmware-vmrc.exe build 158248 in VMware Remote Console (aka VMrc) allows remote attackers to execute arbitrary code via unspecified vectors.    10  High  2017-01-07  2013-05-14  View
51171  CVE-2009-4018  The proc_open function in ext/standard/proc_open.c in PHP before 5.2.11 and 5.3.x before 5.3.1 does not enforce the (1) safe_mode_allowed_env_vars and (2) safe_mode_protected_env_vars directives, which allows context-dependent attackers to execute programs with an arbitrary environment via the env parameter, as demonstrated by a crafted value of the LD_LIBRARY_PATH environment variable.    7.5  High  2017-01-07  2011-07-18  View
51427  CVE-2009-4304  Moodle 1.8 before 1.8.11 and 1.9 before 1.9.7 does not use a random password salt in config.php, which makes it easier for attackers to conduct brute-force password guessing attacks.    7.5  High  2017-01-07  2009-12-17  View

Page 15758 of 17672, showing 5 records out of 88360 total, starting on record 78786, ending on 78790

Actions