NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48633 | CVE-2009-1347 | Multiple SQL injection vulnerabilities in stats/index.php in chCounter 3.1.3 allow remote attackers to execute arbitrary SQL commands via (1) the login_name parameter (aka the username field) or (2) the login_pw parameter (aka the password field). | 2 | 6.8 | Medium | 2017-01-07 | 2009-04-20 | View | |
48889 | CVE-2009-1620 | Multiple cross-site scripting (XSS) vulnerabilities in input.php in MataChat allow remote attackers to inject arbitrary web script or HTML via the (1) nickname and (2) color parameters. | 2 | 4.3 | Medium | 2017-01-07 | 2009-05-12 | View | |
49145 | CVE-2009-1880 | Cross-site scripting (XSS) vulnerability in MT312 REP-BBS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) model.php and (2) config.php with timestamps before 20090521. | 2 | 4.3 | Medium | 2017-01-07 | 2009-06-02 | View | |
49401 | CVE-2009-2139 | Heap-based buffer overflow in svtools/source/filter.vcl/wmf/enhwmf.cxx in Go-oo 2.x and 3.x before 3.0.1, previously named ooo-build and related to OpenOffice.org (OOo), allows remote attackers to execute arbitrary code via a crafted EMF file, a similar issue to CVE-2008-2238. | 2 | 9.3 | High | 2017-01-07 | 2010-07-19 | View | |
49657 | CVE-2009-2410 | The local_handler_callback function in server/responder/pam/pam_LOCAL_domain.c in sssd 0.4.1 does not properly handle blank-password accounts in the SSSD BE database, which allows context-dependent attackers to obtain access by sending the account"s username, in conjunction with an arbitrary password, over an ssh connection. | 2 | 7.5 | High | 2017-01-07 | 2009-08-08 | View |
Page 17299 of 17672, showing 5 records out of 88360 total, starting on record 86491, ending on 86495