NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48363 | CVE-2009-1053 | chaozzDB 1.2 and earlier stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing user credentials via a direct request for user.tsv. | 2 | 5 | Medium | 2017-01-07 | 2009-03-24 | View | |
48619 | CVE-2009-1332 | The Online Help feature in Sun Java System Directory Server 5.2 and Enterprise Edition 5 allows remote attackers to determine the existence of files and directories, and possibly obtain partial contents of files, via unspecified vectors. | 2 | 5 | Medium | 2017-01-07 | 2009-04-28 | View | |
48875 | CVE-2009-1606 | Multiple stack-based and heap-based buffer overflows in Dafolo DafoloControl ActiveX control (DafoloFFControl.dll) 1.108.6.195 allow remote attackers to execute arbitrary code via long (1) baseurl, (2) kommune, (3) felter, (4) afdeling, (5) Flags, (6) HelpURL, (7) caburl, or (8) filename properties; or (9) a long argument to the Open method. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 9.3 | High | 2017-01-07 | 2009-05-12 | View | |
49131 | CVE-2009-1865 | Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors, related to a "null pointer vulnerability." | 2 | 9.3 | High | 2017-01-07 | 2013-11-02 | View | |
49387 | CVE-2009-2125 | delete_bug.php in Elvin before 1.2.1 does not require administrative privileges, which allows remote authenticated users to bypass intended access restrictions and delete arbitrary bugs. | 2 | 4 | Medium | 2017-01-07 | 2009-06-23 | View |
Page 16300 of 17672, showing 5 records out of 88360 total, starting on record 81496, ending on 81500