NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48082  CVE-2009-0763  Cross-site scripting (XSS) vulnerability in default.php in Kipper 2.01 allows remote attackers to inject arbitrary web script or HTML via the charm parameter.    4.3  Medium  2017-01-07  2009-06-17  View
48594  CVE-2009-1307  The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI.    6.8  Medium  2017-01-07  2010-08-21  View
48850  CVE-2009-1581  functions/mime.php in SquirrelMail before 1.4.18 does not protect the application"s content from Cascading Style Sheets (CSS) positioning in HTML e-mail messages, which allows remote attackers to spoof the user interface, and conduct cross-site scripting (XSS) and phishing attacks, via a crafted message.    4.3  Medium  2017-01-07  2010-08-21  View
49362  CVE-2009-2100  Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows remote attackers to read arbitrary files via directory traversal sequences in the section parameter to index.php.    Medium  2017-01-07  2009-10-08  View
49618  CVE-2009-2371  Advanced Forum 6.x before 6.x-1.1, a module for Drupal, does not prevent users from modifying user signatures after the associated comment format has been changed to an administrator-controlled input format, which allows remote authenticated users to inject arbitrary web script, HTML, and possibly PHP code via a crafted user signature.    6.5  Medium  2017-01-07  2009-07-08  View

Page 16064 of 17672, showing 5 records out of 88360 total, starting on record 80316, ending on 80320

Actions