NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
49390 | CVE-2009-2128 | SQL injection vulnerability in close_bug.php in Elvin before 1.2.1 allows remote attackers to execute arbitrary SQL commands via the title (aka subject) field. | 2 | 7.5 | High | 2017-01-07 | 2009-06-22 | View | |
49646 | CVE-2009-2399 | PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-07-09 | View | |
49902 | CVE-2009-2661 | The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data. NOTE: this is due to an incomplete fix for CVE-2009-2185. | 2 | 5 | Medium | 2017-01-07 | 2009-11-24 | View | |
50158 | CVE-2009-2937 | Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed. | 2 | 4.3 | Medium | 2017-01-07 | 2009-09-18 | View | |
50414 | CVE-2009-3209 | SQL injection vulnerability in remove.php in PHP eMail Manager 3.3.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-09-17 | View |
Page 16505 of 17672, showing 5 records out of 88360 total, starting on record 82521, ending on 82525