NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48870  CVE-2009-1601  The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of the current working directory to the clamav account, which might allow local users to bypass intended access restrictions via read or write operations involving this directory.    6.8  Medium  2017-01-07  2009-05-12  View
49126  CVE-2009-1860  Unspecified vulnerability in Adobe Shockwave Player before 11.5.0.600 allows remote attackers to execute arbitrary code via crafted Shockwave Player 10 content.    9.3  High  2017-01-07  2009-07-01  View
49382  CVE-2009-2120  Multiple SQL injection vulnerabilities in TekBase All-in-One 3.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) ids parameter to admin.php, the (2) y parameter to members.php, and other unspecified vectors. NOTE: vector 1 requires administrative access.    6.5  Medium  2017-01-07  2009-07-01  View
49638  CVE-2009-2391  Cross-site scripting (XSS) vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to inject arbitrary web script or HTML via the tid parameter.    4.3  Medium  2017-01-07  2009-07-09  View
49894  CVE-2009-2653  ** DISPUTED ** The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the significance of this report, stating that "the Administrator to SYSTEM "escalation" is not a security boundary we defend."    4.6  Medium  2017-01-07  2009-08-11  View

Page 16146 of 17672, showing 5 records out of 88360 total, starting on record 80726, ending on 80730

Actions