NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
50670 | CVE-2009-3469 | Cross-site scripting (XSS) vulnerability in profiles/html/simpleSearch.do in IBM Lotus Connections 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the name parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-10-03 | View | |
51182 | CVE-2009-4029 | The (1) dist or (2) distcheck rules in GNU Automake 1.11.1, 1.10.3, and release branches branch-1-4 through branch-1-9, when producing a distribution tarball for a package that uses Automake, assign insecure permissions (777) to directories in the build tree, which introduces a race condition that allows local users to modify the contents of package files, introduce Trojan horse programs, or conduct other attacks before the build is complete. | 2 | 4.4 | Medium | 2017-01-07 | 2012-08-08 | View | |
51438 | CVE-2009-4315 | Directory traversal vulnerability in admin/ajaxsave.php in Nuggetz CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers to create or modify arbitrary files via a .. (dot dot) in the nugget parameter and a modified pagevalue parameter, as demonstrated by creating and accessing a .php file to execute arbitrary PHP code. | 2 | 6.8 | Medium | 2017-01-07 | 2009-12-15 | View | |
51950 | CVE-2009-4833 | MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allows remote attackers to perform a man-in-the-middle attack with a spoofed SSL certificate. | 2 | 5.8 | Medium | 2017-01-07 | 2010-04-30 | View | |
52206 | CVE-2009-5110 | dhttpd allows remote attackers to cause a denial of service (daemon outage) via partial HTTP requests, as demonstrated by Slowloris. | 2 | 5 | Medium | 2017-01-07 | 2011-12-28 | View |
Page 17050 of 17672, showing 5 records out of 88360 total, starting on record 85246, ending on 85250