NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
50227  CVE-2009-3010  Mozilla Firefox 3.0.13 and earlier, 3.5, 3.6 a1 pre, and 3.7 a1 pre; SeaMonkey 1.1.17; and Mozilla 1.7.x and earlier do not properly block data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header. NOTE: in some product versions, the JavaScript executes outside of the context of the HTTP site.    4.3  Medium  2017-01-07  2009-09-05  View
50483  CVE-2009-3278  The QNAP TS-239 Pro and TS-639 Pro with firmware 2.1.7 0613, 3.1.0 0627, and 3.1.1 0815 use the rand library function to generate a certain recovery key, which makes it easier for local users to determine this key via a brute-force attack.    4.9  Medium  2017-01-07  2010-03-18  View
50739  CVE-2009-3539  Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Ultra Classifieds Pro allow remote attackers to inject arbitrary web script or HTML via the (1) cname parameter to subclass.php and the (2) sn parameter to listads.php.    4.3  Medium  2017-01-07  2009-10-05  View
50995  CVE-2009-3828  The web interface for Everfocus EDR1600 DVR allows remote attackers to bypass authentication and access live cams via certain vectors.    Medium  2017-01-07  2009-11-02  View
51507  CVE-2009-4384  Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net Ez Poll Hoster (EPH) allow remote attackers to inject arbitrary web script or HTML via the (1) pid parameter in a code action to index.php and the (2) uid parameter in a view action to profile.php.    4.3  Medium  2017-01-07  2009-12-23  View

Page 1862 of 17672, showing 5 records out of 88360 total, starting on record 9306, ending on 9310

Actions