NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
50636  CVE-2009-3435  Cross-site scripting (XSS) vulnerability in the variable editor in the Devel module 5.x before 5.x-1.2 and 6.x before 6.x-1.18, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via a variable name.    4.3  Medium  2017-01-07  2009-10-09  View
50892  CVE-2009-3706  Unspecified vulnerability in the ZFS filesystem in Sun Solaris 10, and OpenSolaris snv_100 through snv_117, allows local users to bypass intended limitations of the file_chown_self privilege via certain uses of the chown system call.    4.4  Medium  2017-01-07  2009-10-16  View
51148  CVE-2009-3989  Bugzilla before 3.0.11, 3.2.x before 3.2.6, 3.4.x before 3.4.5, and 3.5.x before 3.5.3 does not block access to files and directories that are used by custom installations, which allows remote attackers to obtain sensitive information via requests for (1) CVS/, (2) contrib/, (3) docs/en/xml/, (4) t/, or (5) old-params.txt.    4.3  Medium  2017-01-07  2010-02-05  View
51660  CVE-2009-4543  PHP remote file inclusion vulnerability in index.php in Cromosoft Technologies Facil Helpdesk 2.3 Lite allows remote attackers to execute arbitrary PHP code via a URL in the lng parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.    6.8  Medium  2017-01-07  2010-01-04  View
51916  CVE-2009-4799  Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for (1) artikler_prod.mdb or (2) medlemmer.mdb.    Medium  2017-01-07  2010-04-23  View

Page 15851 of 17672, showing 5 records out of 88360 total, starting on record 79251, ending on 79255

Actions