NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48864 | CVE-2009-1595 | The jabber:iq:auth implementation in IQAuthHandler.java in Ignite Realtime Openfire before 3.6.4 allows remote authenticated users to change the passwords of arbitrary accounts via a modified username element in a passwd_change action. | 2 | 4 | Medium | 2017-01-07 | 2009-05-11 | View | |
49376 | CVE-2009-2114 | Multiple cross-site scripting (XSS) vulnerabilities in admin.php in SkyBlueCanvas 1.1 r237 allow remote attackers to inject arbitrary web script or HTML via the (1) mgroup, (2) mgr, (3) objtype, (4) id, and (5) dir parameters. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-19 | View | |
49888 | CVE-2009-2647 | Unspecified vulnerability in Kaspersky Anti-Virus 2010 and Kaspersky Internet Security 2010 before Critical Fix 9.0.0.463 allows remote attackers to disable the Kaspersky application via unknown attack vectors unrelated to "an external script." | 2 | 5 | Medium | 2017-01-07 | 2009-07-31 | View | |
50144 | CVE-2009-2923 | Multiple directory traversal vulnerabilities in BitmixSoft PHP-Lance 1.52 allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) language parameter to show.php and (2) in parameter to advanced_search.php. | 2 | 5 | Medium | 2017-01-07 | 2009-08-26 | View | |
50400 | CVE-2009-3195 | Multiple cross-site scripting (XSS) vulnerabilities in JCE-Tech Auction RSS Content Script 3.0 allow remote attackers to inject arbitrary web script or HTML via the id parameter to (1) rss.php and (2) search.php. | 2 | 4.3 | Medium | 2017-01-07 | 2009-09-16 | View |
Page 16562 of 17672, showing 5 records out of 88360 total, starting on record 82806, ending on 82810