NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
49388 | CVE-2009-2126 | Cross-site scripting (XSS) vulnerability in close_bug.php in Elvin before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the title (aka subject) field. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-22 | View | |
49644 | CVE-2009-2397 | Directory traversal vulnerability in download.php in Audio Article Directory allows remote attackers to read arbitrary files via directory traversal sequences in the file parameter. | 2 | 5 | Medium | 2017-01-07 | 2009-07-09 | View | |
49900 | CVE-2009-2659 | The Admin media handler in core/servers/basehttp.py in Django 1.0 and 0.96 does not properly map URL requests to expected "static media files," which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a crafted URL. | 2 | 5 | Medium | 2017-01-07 | 2009-08-12 | View | |
50156 | CVE-2009-2935 | Google V8, as used in Google Chrome before 2.0.172.43, allows remote attackers to bypass intended restrictions on reading memory, and possibly obtain sensitive information or execute arbitrary code in the Chrome sandbox, via crafted JavaScript. | 2 | 10 | High | 2017-01-07 | 2009-09-04 | View | |
50412 | CVE-2009-3207 | The ImageCache module 5.x before 5.x-2.5 and 6.x before 6.x-2.0-beta10, a module for Drupal, when the private file system is used, does not properly perform access control for derivative images, which allows remote attackers to view arbitrary images via a request that specifies an image"s filename. | 2 | 6.8 | Medium | 2017-01-07 | 2009-09-17 | View |
Page 16018 of 17672, showing 5 records out of 88360 total, starting on record 80086, ending on 80090