NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
46642 | CVE-2012-5514 | The guest_physmap_mark_populate_on_demand function in Xen 4.2 and earlier does not properly unlock the subject GFNs when checking if they are in use, which allows local guest HVM administrators to cause a denial of service (hang) via unspecified vectors. | 2 | 4.7 | Medium | 2017-01-19 | 2014-04-19 | View | |
46898 | CVE-2012-5882 | Cross-site scripting (XSS) vulnerability in the Flash component infrastructure in YUI 2.5.0 through 2.9.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to uploader.swf, a similar issue to CVE-2010-4208. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-20 | View | |
47922 | CVE-2009-0593 | SQL injection vulnerability in members.php in plx Auto Reminder 3.7 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a newar action. | 2 | 6.5 | Medium | 2017-01-07 | 2009-02-17 | View | |
48690 | CVE-2009-1414 | Google Chrome 2.0.x lets modifications to the global object persist across a page transition, which makes it easier for attackers to conduct Universal XSS attacks via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-07 | 2009-05-15 | View | |
48946 | CVE-2009-1677 | Multiple static code injection vulnerabilities in the saveFeed function in rss/feedcreator.class.php in Bitweaver 2.6 and earlier allow (1) remote authenticated users to inject arbitrary PHP code into files by placing PHP sequences into the account"s "display name" setting and then invoking boards/boards_rss.php, and might allow (2) remote attackers to inject arbitrary PHP code into files via the HTTP Host header in a request to boards/boards_rss.php. | 2 | 6.5 | Medium | 2017-01-07 | 2009-06-09 | View |
Page 1827 of 17672, showing 5 records out of 88360 total, starting on record 9131, ending on 9135