NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
50925 | CVE-2009-3745 | Cross-site scripting (XSS) vulnerability in the help pages in IBM Rational AppScan Enterprise Edition 5.5.0.2 allows remote attackers to inject arbitrary web script or HTML via the query string. | 2 | 4.3 | Medium | 2017-01-07 | 2009-11-20 | View | |
51181 | CVE-2009-4028 | The vio_verify_callback function in viosslfactories.c in MySQL 5.0.x before 5.0.88 and 5.1.x before 5.1.41, when OpenSSL is used, accepts a value of zero for the depth of X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL-based MySQL servers via a crafted certificate, as demonstrated by a certificate presented by a server linked against the yaSSL library. | 2 | 6.8 | Medium | 2017-01-07 | 2011-06-24 | View | |
51437 | CVE-2009-4314 | Sun Ray Server Software 4.1 on Solaris 10, when Automatic Multi-Group Hotdesking (AMGH) is enabled, responds to a logout action by immediately logging the user in again, which makes it easier for physically proximate attackers to obtain access to a session by going to an unattended DTU device. | 2 | 4.4 | Medium | 2017-01-07 | 2009-12-15 | View | |
51693 | CVE-2009-4576 | SQL injection vulnerability in the BeeHeard (com_beeheard) component 1.x for Joomla! allows remote attackers to execute arbitrary SQL commands via the category_id parameter in a suggestions action to index.php. | 2 | 7.5 | High | 2017-01-07 | 2010-01-07 | View | |
51949 | CVE-2009-4832 | The dlpcrypt.sys kernel driver 0.1.1.27 in DESlock+ 4.0.2 allows local users to gain privileges via a crafted IOCTL 0x80012010 request to the DLPCryptCore device. | 2 | 7.2 | High | 2017-01-07 | 2010-04-30 | View |
Page 16087 of 17672, showing 5 records out of 88360 total, starting on record 80431, ending on 80435