NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48892 | CVE-2009-1623 | Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary web script or HTML via the PID parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-05-13 | View | |
49148 | CVE-2009-1883 | The z90crypt_unlocked_ioctl function in the z90crypt driver in the Linux kernel 2.6.9 does not perform a capability check for the Z90QUIESCE operation, which allows local users to leverage euid 0 privileges to force a driver outage. | 2 | 4.4 | Medium | 2017-01-07 | 2012-03-19 | View | |
49404 | CVE-2009-2142 | Multiple SQL injection vulnerabilities in admin/index.asp in Zip Store Chat 4.0 and 5.0 allow remote attackers to execute arbitrary SQL commands via the (1) login and (2) senha parameters. | 2 | 7.5 | High | 2017-01-07 | 2009-06-23 | View | |
49660 | CVE-2009-2414 | Stack consumption vulnerability in libxml2 2.5.10, 2.6.16, 2.6.26, 2.6.27, and 2.6.32, and libxml 1.8.17, allows context-dependent attackers to cause a denial of service (application crash) via a large depth of element declarations in a DTD, related to a function recursion, as demonstrated by the Codenomicon XML fuzzing framework. | 2 | 4.3 | Medium | 2017-01-07 | 2014-10-24 | View | |
49916 | CVE-2009-2675 | Integer overflow in the unpack200 utility in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 15, and JDK and JRE 5.0 before Update 20, allows context-dependent attackers to gain privileges via unspecified length fields in the header of a Pack200-compressed JAR file, which leads to a heap-based buffer overflow during decompression. | 2 | 10 | High | 2017-01-07 | 2012-10-22 | View |
Page 17481 of 17672, showing 5 records out of 88360 total, starting on record 87401, ending on 87405