NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49638  CVE-2009-2391  Cross-site scripting (XSS) vulnerability in text.php in Virtuenetz Virtue Online Test Generator allows remote attackers to inject arbitrary web script or HTML via the tid parameter.    4.3  Medium  2017-01-07  2009-07-09  View
49894  CVE-2009-2653  ** DISPUTED ** The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows local administrators to bypass unspecified "security software" and gain privileges via a crafted call that triggers an overwrite of an arbitrary memory location. NOTE: the vendor disputes the significance of this report, stating that "the Administrator to SYSTEM "escalation" is not a security boundary we defend."    4.6  Medium  2017-01-07  2009-08-11  View
50406  CVE-2009-3201  Integer overflow in Media Player Classic 6.4.9 allows user-assisted remote attackers to cause a denial of service (application crash) via a MIDI file (.mid) with a malformed header, which triggers a buffer overflow, a different vulnerability than CVE-2007-4940.    4.3  Medium  2017-01-07  2009-09-16  View
51174  CVE-2009-4021  The fuse_direct_io function in fs/fuse/file.c in the fuse subsystem in the Linux kernel before 2.6.32-rc7 might allow attackers to cause a denial of service (invalid pointer dereference and OOPS) via vectors possibly related to a memory-consumption attack.    4.9  Medium  2017-01-07  2012-03-19  View
51942  CVE-2009-4825  8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for App_Data/sb.mdb.    Medium  2017-01-07  2010-05-24  View

Page 16782 of 17672, showing 5 records out of 88360 total, starting on record 83906, ending on 83910

Actions