NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49380  CVE-2009-2118  Integer overflow in IrfanView 4.23, when the resampling or screen fitting option is enabled, allows remote attackers to execute arbitrary code via a crafted TIFF 1 BPP image, which triggers a heap-based buffer overflow.    6.8  Medium  2017-01-07  2009-06-24  View
49636  CVE-2009-2389  Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) jahr or (2) idneu parameter in an archive action, or (3) the newsid parameter.    6.8  Medium  2017-01-07  2009-07-16  View
49892  CVE-2009-2651  main/rtp.c in Asterisk Open Source 1.6.1 before 1.6.1.2 allows remote attackers to cause a denial of service (crash) via an RTP text frame without a certain delimiter, which triggers a NULL pointer dereference and the subsequent calculation of an invalid pointer.    Medium  2017-01-07  2009-08-06  View
50148  CVE-2009-2927  SQL injection vulnerability in DetailFile.php in DigitalSpinners DS CMS 1.0 allows remote attackers to execute arbitrary SQL commands via the nFileId parameter.    7.5  High  2017-01-07  2009-08-21  View
50404  CVE-2009-3199  Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database with usernames and password hashes via a direct request for system_admin/admin.ucf.    Medium  2017-01-07  2009-09-16  View

Page 16026 of 17672, showing 5 records out of 88360 total, starting on record 80126, ending on 80130

Actions