NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
49134 | CVE-2009-1868 | Heap-based buffer overflow in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unspecified vectors involving URL parsing. | 2 | 9.3 | High | 2017-01-07 | 2013-11-02 | View | |
49390 | CVE-2009-2128 | SQL injection vulnerability in close_bug.php in Elvin before 1.2.1 allows remote attackers to execute arbitrary SQL commands via the title (aka subject) field. | 2 | 7.5 | High | 2017-01-07 | 2009-06-22 | View | |
49646 | CVE-2009-2399 | PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-07-09 | View | |
49902 | CVE-2009-2661 | The asn1_length function in strongSwan 2.8 before 2.8.11, 4.2 before 4.2.17, and 4.3 before 4.3.3 does not properly handle X.509 certificates with crafted Relative Distinguished Names (RDNs), which allows remote attackers to cause a denial of service (pluto IKE daemon crash) via malformed ASN.1 data. NOTE: this is due to an incomplete fix for CVE-2009-2185. | 2 | 5 | Medium | 2017-01-07 | 2009-11-24 | View | |
50158 | CVE-2009-2937 | Cross-site scripting (XSS) vulnerability in Planet 2.0 and Planet Venus allows remote attackers to inject arbitrary web script or HTML via the SRC attribute of an IMG element in a feed. | 2 | 4.3 | Medium | 2017-01-07 | 2009-09-18 | View |
Page 16634 of 17672, showing 5 records out of 88360 total, starting on record 83166, ending on 83170