NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
47668 | CVE-2009-0336 | Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request for database/Blog.mdb. NOTE: some of these details are obtained from third party information. | 2 | 5 | Medium | 2017-01-07 | 2009-01-29 | View | |
47924 | CVE-2009-0595 | PHP remote file inclusion vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the theme parameter. | 2 | 5.1 | Medium | 2017-01-07 | 2009-02-17 | View | |
49460 | CVE-2009-2198 | Apple GarageBand before 5.1 reconfigures Safari to accept all cookies regardless of domain name, which makes it easier for remote web servers to track users. | 2 | 4.3 | Medium | 2017-01-07 | 2009-08-18 | View | |
49972 | CVE-2009-2739 | Cross-site scripting (XSS) vulnerability in FreeNAS before 0.69.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | 2 | 4.3 | Medium | 2017-01-07 | 2009-09-02 | View | |
50228 | CVE-2009-3011 | Google Chrome 1.0.154.48 and earlier, 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta does not properly block data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header. NOTE: the JavaScript executes outside of the context of the HTTP site. | 2 | 4.3 | Medium | 2017-01-07 | 2009-09-05 | View |
Page 1895 of 17672, showing 5 records out of 88360 total, starting on record 9471, ending on 9475