NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48870 | CVE-2009-1601 | The Ubuntu clamav-milter.init script in clamav-milter before 0.95.1+dfsg-1ubuntu1.2 in Ubuntu 9.04 sets the ownership of the current working directory to the clamav account, which might allow local users to bypass intended access restrictions via read or write operations involving this directory. | 2 | 6.8 | Medium | 2017-01-07 | 2009-05-12 | View | |
49126 | CVE-2009-1860 | Unspecified vulnerability in Adobe Shockwave Player before 11.5.0.600 allows remote attackers to execute arbitrary code via crafted Shockwave Player 10 content. | 2 | 9.3 | High | 2017-01-07 | 2009-07-01 | View | |
49382 | CVE-2009-2120 | Multiple SQL injection vulnerabilities in TekBase All-in-One 3.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) ids parameter to admin.php, the (2) y parameter to members.php, and other unspecified vectors. NOTE: vector 1 requires administrative access. | 2 | 6.5 | Medium | 2017-01-07 | 2009-07-01 | View | |
49638 | CVE-2009-2391 | Cross-site scripting (XSS) vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to inject arbitrary web script or HTML via the tid parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-07-09 | View | |
49894 | CVE-2009-2653 | ** DISPUTED ** The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the significance of this report, stating that "the Administrator to SYSTEM "escalation" is not a security boundary we defend." | 2 | 4.6 | Medium | 2017-01-07 | 2009-08-11 | View |
Page 16146 of 17672, showing 5 records out of 88360 total, starting on record 80726, ending on 80730