NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49968  CVE-2009-2735  SQL injection vulnerability in admin.php in sun-jester OpenNews 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.    6.8  Medium  2017-01-07  2009-08-11  View
50224  CVE-2009-3007  Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.    4.3  Medium  2017-01-07  2009-09-05  View
50480  CVE-2009-3275  Blocks/Common/Src/Configuration/Manageability/Adm/AdmContentBuilder.cs in Microsoft patterns & practices Enterprise Library (aka EntLib) allows context-dependent attackers to cause a denial of service (CPU consumption) via an input string composed of many (backslash) characters followed by a " (double quote), related to a certain regular expression, aka a "ReDoS" vulnerability.    Medium  2017-01-07  2009-09-22  View
51248  CVE-2009-4098  Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticated users with banner / file upload permissions to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in an images directory.    Medium  2017-01-07  2011-07-25  View
51504  CVE-2009-4381  Cross-site scripting (XSS) vulnerability in index.php in texmedia Million Pixel Script 3 allows remote attackers to inject arbitrary web script or HTML via the pa parameter. NOTE: some of these details are obtained from third party information.    4.3  Medium  2017-01-07  2009-12-23  View

Page 1758 of 17672, showing 5 records out of 88360 total, starting on record 8786, ending on 8790

Actions