NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
51946 | CVE-2009-4829 | Cross-site scripting (XSS) vulnerability in the Automated Logout module 6.x-1.x before 6.x-1.7 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users with administer autologout privileges to inject arbitrary web script or HTML via unspecified vectors. | 2 | 2.1 | Low | 2017-01-07 | 2010-04-28 | View | |
52202 | CVE-2009-5101 | Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, referer headers, or sniffing of web traffic. | 2 | 5 | Medium | 2017-01-07 | 2011-09-14 | View | |
52458 | CVE-2007-0229 | Integer overflow in the ffs_mountfs function in Mac OS X 10.4.8 and FreeBSD 6.1 allows local users to cause a denial of service (panic) and possibly gain privileges via a crafted DMG image that causes "allocation of a negative size buffer" leading to a heap-based buffer overflow, a related issue to CVE-2006-5679. NOTE: a third party states that this issue does not cross privilege boundaries in FreeBSD because only root may mount a filesystem. | 2 | 7.2 | High | 2017-01-07 | 2011-10-11 | View | |
52714 | CVE-2007-0490 | index.php in Open-Realty 2.3.4 allows remote attackers to obtain sensitive information (the full path) via an invalid listingID parameter in a listingview action. | 2 | 5 | Medium | 2017-01-07 | 2008-09-05 | View | |
52970 | CVE-2007-0749 | Multiple stack-based buffer overflows in the is_command function in proxy.c in Apple Darwin Streaming Proxy, when using Darwin Streaming Server before 5.5.5, allow remote attackers to execute arbitrary code via a long (1) cmd or (2) server value in an RTSP request. | 2 | 10 | High | 2017-01-07 | 2011-03-07 | View |
Page 15884 of 17672, showing 5 records out of 88360 total, starting on record 79416, ending on 79420