NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
49898 | CVE-2009-2657 | nilfs-utils before 2.0.14 installs multiple programs with unnecessary setuid privileges, which allows local users to execute arbitrary commands via the device string in a -c command line option to mkfs.nilfs2. | 2 | 4.6 | Medium | 2017-01-07 | 2009-08-05 | View | |
50922 | CVE-2009-3742 | Cross-site scripting (XSS) vulnerability in Liferay Portal before 5.3.0 allows remote attackers to inject arbitrary web script or HTML via the p_p_id parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2010-01-08 | View | |
51690 | CVE-2009-4573 | Multiple cross-site scripting (XSS) vulnerabilities in the Joomulus (mod_joomulus) module 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action to (1) tagcloud_ell.swf, (2) tagcloud_eng.swf, (3) tagcloud_por.swf, (4) tagcloud_rus.swf, and possibly (5) tagcloud_jpn.swf. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | 2 | 4.3 | Medium | 2017-01-07 | 2010-01-07 | View | |
52202 | CVE-2009-5101 | Pentaho BI Server 1.7.0.1062 and earlier includes the session ID (JSESSIONID) in the URL, which allows attackers to obtain it from session history, referer headers, or sniffing of web traffic. | 2 | 5 | Medium | 2017-01-07 | 2011-09-14 | View | |
52714 | CVE-2007-0490 | index.php in Open-Realty 2.3.4 allows remote attackers to obtain sensitive information (the full path) via an invalid listingID parameter in a listingview action. | 2 | 5 | Medium | 2017-01-07 | 2008-09-05 | View |
Page 16913 of 17672, showing 5 records out of 88360 total, starting on record 84561, ending on 84565