NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
50636 | CVE-2009-3435 | Cross-site scripting (XSS) vulnerability in the variable editor in the Devel module 5.x before 5.x-1.2 and 6.x before 6.x-1.18, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a variable name. | 2 | 4.3 | Medium | 2017-01-07 | 2009-10-09 | View | |
50892 | CVE-2009-3706 | Unspecified vulnerability in the ZFS filesystem in Sun Solaris 10, and OpenSolaris snv_100 through snv_117, allows local users to bypass intended limitations of the file_chown_self privilege via certain uses of the chown system call. | 2 | 4.4 | Medium | 2017-01-07 | 2009-10-16 | View | |
51148 | CVE-2009-3989 | Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt. | 2 | 4.3 | Medium | 2017-01-07 | 2010-02-05 | View | |
51660 | CVE-2009-4543 | PHP remote file inclusion vulnerability in index.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to execute arbitrary PHP code via a URL in the lng parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences. | 2 | 6.8 | Medium | 2017-01-07 | 2010-01-04 | View | |
51916 | CVE-2009-4799 | Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) artikler_prod.mdb or (2) medlemmer.mdb. | 2 | 5 | Medium | 2017-01-07 | 2010-04-23 | View |
Page 15851 of 17672, showing 5 records out of 88360 total, starting on record 79251, ending on 79255