NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
47612 | CVE-2009-0278 | Sun Java System Application Server (AS) 8.1 and 8.2 allows remote attackers to read the Web Application configuration files in the (1) WEB-INF or (2) META-INF directory via a malformed request. | 2 | 5 | Medium | 2017-01-07 | 2011-03-07 | View | |
47868 | CVE-2009-0536 | at in bos.rte.cron on IBM AIX 5.2.0, 5.3.0 through 5.3.9, and 6.1.0 through 6.1.2 allows local users to read arbitrary files via unspecified vectors, related to failure to drop root privileges. | 2 | 4.9 | Medium | 2017-01-07 | 2011-03-07 | View | |
48380 | CVE-2009-1070 | Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via the avatar parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-03-27 | View | |
48892 | CVE-2009-1623 | Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary web script or HTML via the PID parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2009-05-13 | View | |
49148 | CVE-2009-1883 | The z90crypt_unlocked_ioctl function in the z90crypt driver in the Linux kernel 2.6.9 does not perform a capability check for the Z90QUIESCE operation, which allows local users to leverage euid 0 privileges to force a driver outage. | 2 | 4.4 | Medium | 2017-01-07 | 2012-03-19 | View |
Page 17562 of 17672, showing 5 records out of 88360 total, starting on record 87806, ending on 87810