NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49649  CVE-2009-2402  SQL injection vulnerability in index.php in the forum module in PHPEcho CMS 2.0-rc3 allows remote attackers to execute arbitrary SQL commands via the id parameter in a thread action, a different vector than CVE-2008-0355.    7.5  High  2017-01-07  2009-07-09  View
49905  CVE-2009-2664  The js_watch_set function in js/src/jsdbgapi.cpp in the JavaScript engine in Mozilla Firefox before 3.0.12 allows remote attackers to cause a denial of service (assertion failure and application exit) or possibly execute arbitrary code via a crafted .js file, related to a "memory safety bug." NOTE: this was originally reported as affecting versions before 3.0.13.    Medium  2017-01-07  2010-08-21  View
50161  CVE-2009-2942  The mysql-ocaml bindings 1.0.4 for MySQL do not properly support the mysql_real_escape_string function, which might allow remote attackers to leverage escaping issues involving multibyte character encodings.    7.5  High  2017-01-07  2009-10-27  View
50417  CVE-2009-3212  SQL injection vulnerability in VivaPrograms Infinity Script 2.x.x, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username field.    6.8  Medium  2017-01-07  2009-09-17  View
50673  CVE-2009-3472  IBM DB2 8 before FP18, 9.1 before FP8, and 9.5 before FP4 allows remote authenticated users to bypass intended access restrictions, and update, insert, or delete table rows, via unspecified vectors.    6.5  Medium  2017-01-07  2009-10-14  View

Page 16358 of 17672, showing 5 records out of 88360 total, starting on record 81786, ending on 81790

Actions