NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49882  CVE-2009-2641  PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.    6.8  Medium  2017-01-07  2009-07-29  View
50138  CVE-2009-2917  Stack-based buffer overflow in ImTOO MPEG Encoder 3.1.53 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted string in a (1) .cue or (2) .m3u playlist file.    4.3  Medium  2017-01-07  2009-09-04  View
50394  CVE-2009-3189  Cross-site scripting (XSS) vulnerability in search.php in DigiOz Guestbook 1.7.2 allows remote attackers to inject arbitrary web script or HTML via the search_term parameter.    4.3  Medium  2017-01-07  2009-09-16  View
50650  CVE-2009-3449  MP3 Collector 2.3 allows remote attackers to cause a denial of service (application crash) via a long URL in a .m3u playlist file.    4.3  Medium  2017-01-07  2009-09-30  View
50906  CVE-2009-3720  The updatePosition function in lib/xmltok_impl.c in libexpat in Expat 2.0.1, as used in Python, PyXML, w3c-libwww, and other software, allows context-dependent attackers to cause a denial of service (application crash) via an XML document with crafted UTF-8 sequences that trigger a buffer over-read, a different vulnerability than CVE-2009-2625.    Medium  2017-01-07  2016-08-22  View

Page 16357 of 17672, showing 5 records out of 88360 total, starting on record 81781, ending on 81785

Actions