NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
49682 | CVE-2009-2437 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Rentventory 1.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) username (aka Login) and (2) password parameters in a login action. | 2 | 4.3 | Medium | 2017-01-07 | 2009-07-13 | View | |
49938 | CVE-2009-2697 | The Red Hat build script for the GNOME Display Manager (GDM) before 2.16.0-56 on Red Hat Enterprise Linux (RHEL) 5 omits TCP Wrapper support, which might allow remote attackers to bypass intended access restrictions via XDMCP connections, a different vulnerability than CVE-2007-5079. | 2 | 6.8 | Medium | 2017-01-07 | 2010-08-21 | View | |
50194 | CVE-2009-2977 | The Cisco Security Monitoring, Analysis and Response System (CS-MARS) 6.0.4 and earlier stores cleartext passwords in log/sysbacktrace.## files within error-logs.tar.gz archives, which allows context-dependent attackers to obtain sensitive information by reading these files. | 2 | 3.3 | Low | 2017-01-07 | 2009-09-04 | View | |
50450 | CVE-2009-3245 | OpenSSL before 0.9.8m does not check for a NULL return value from bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) crypto/bn/bn_gf2m.c, (3) crypto/ec/ec2_smpl.c, and (4) engines/e_ubsec.c, which has unspecified impact and context-dependent attack vectors. | 2 | 10 | High | 2017-01-07 | 2016-08-22 | View | |
50706 | CVE-2009-3505 | SQL injection vulnerability in view_news.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL commands via the news_id parameter. NOTE: the game_id vector is already covered by CVE-2008-4460. | 2 | 7.5 | High | 2017-01-07 | 2009-10-01 | View |
Page 1631 of 17672, showing 5 records out of 88360 total, starting on record 8151, ending on 8155