NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
47849 | CVE-2009-0517 | Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class. NOTE: some of these details are obtained from third party information. | 2 | 10 | High | 2017-01-07 | 2009-02-11 | View | |
48617 | CVE-2009-1330 | Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long filename in a playlist (.pls) file. | 2 | 9.3 | High | 2017-01-07 | 2016-11-29 | View | |
48873 | CVE-2009-1604 | Unspecified vulnerability in LimeSurvey before 1.82 allows remote attackers to execute commands and obtain sensitive data via unknown attack vectors related to /admin/remotecontrol/. | 2 | 7.5 | High | 2017-01-07 | 2009-05-23 | View | |
49129 | CVE-2009-1863 | Unspecified vulnerability in Adobe Flash Player before 9.0.246.0 and 10.x before 10.0.32.18, and Adobe AIR before 1.5.2, allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors, related to a "privilege escalation vulnerability." | 2 | 9.3 | High | 2017-01-07 | 2013-11-02 | View | |
49385 | CVE-2009-2123 | Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (1) inUser (aka Username) and (2) inPass (aka Password) parameters to (a) inc/login.ei, reachable through login.php; and the (3) id parameter to (b) show_bug.php and (c) show_activity.php. NOTE: it was later reported that vector 3c also affects 1.2.2. | 2 | 7.5 | High | 2017-01-07 | 2009-08-24 | View |
Page 16727 of 17672, showing 5 records out of 88360 total, starting on record 83631, ending on 83635