NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
49912 | CVE-2009-2671 | The SOCKS proxy implementation in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows remote attackers to discover the username of the account that invoked an untrusted (1) applet or (2) Java Web Start application via unspecified vectors. | 2 | 5 | Medium | 2017-01-07 | 2012-10-22 | View | |
50168 | CVE-2009-2949 | Integer overflow in the XPMReader::ReadXPM function in filter.vcl/ixpm/svt_xpmread.cxx in OpenOffice.org (OOo) before 3.2 allows remote attackers to execute arbitrary code via a crafted XPM file that triggers a heap-based buffer overflow. | 2 | 9.3 | High | 2017-01-07 | 2014-11-13 | View | |
50424 | CVE-2009-3219 | Directory traversal vulnerability in a.php in AR Web Content Manager (AWCM) 2.1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the a parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-09-17 | View | |
50680 | CVE-2009-3479 | Cross-site scripting (XSS) vulnerability in Bibliography (Biblio) 5.x before 5.x-1.17 and 6.x before 6.x-1.6, a module for Drupal, allows remote attackers, with "create content displayed by the Bibliography module" permissions, to inject arbitrary web script or HTML via a title. | 2 | 4.3 | Medium | 2017-01-07 | 2009-10-01 | View | |
50936 | CVE-2009-3756 | phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in advancedsearch.php, and (4) choicelist.php, which reveals the installation path in an error message. | 2 | 5 | Medium | 2017-01-07 | 2009-10-23 | View |
Page 17187 of 17672, showing 5 records out of 88360 total, starting on record 85931, ending on 85935