NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
50936 | CVE-2009-3756 | phpBMS 0.96 allows remote attackers to obtain sensitive information via a direct request to (1) footer.php, (2) header.php, (3) the show action in advancedsearch.php, and (4) choicelist.php, which reveals the installation path in an error message. | 2 | 5 | Medium | 2017-01-07 | 2009-10-23 | View | |
51192 | CVE-2009-4040 | Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.0.17 and 2.5.x before 2.5.2, when used with Internet Explorer 6 or 7, allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the search page. | 2 | 4.3 | Medium | 2017-01-07 | 2009-11-23 | View | |
51448 | CVE-2009-4325 | The Client Interfaces component in IBM DB2 8.2 before FP18, 9.1 before FP8, 9.5 before FP5, and 9.7 before FP1 does not validate an unspecified pointer, which allows attackers to overwrite "external memory" via unknown vectors, related to a missing "check for null pointers." | 2 | 6.4 | Medium | 2017-01-07 | 2010-06-29 | View | |
51704 | CVE-2009-4587 | Cherokee Web Server 0.5.4 allows remote attackers to cause a denial of service (daemon crash) via an MS-DOS reserved word in a URI, as demonstrated by the AUX reserved word. | 2 | 5 | Medium | 2017-01-07 | 2010-01-08 | View | |
51960 | CVE-2009-4843 | ToutVirtual VirtualIQ Pro before 3.5 build 8691 does not require administrative authentication for JBoss console access, which allows remote attackers to execute arbitrary commands via requests to (1) the JMX Management Console or (2) the Web Console. | 2 | 7.5 | High | 2017-01-07 | 2010-05-21 | View |
Page 17240 of 17672, showing 5 records out of 88360 total, starting on record 86196, ending on 86200