NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49667  CVE-2009-2422  The example code for the digest authentication functionality (http_authentication.rb) in Ruby on Rails before 2.3.3 defines an authenticate_or_request_with_http_digest block that returns nil instead of false when the user does not exist, which allows context-dependent attackers to bypass authentication for applications that are derived from this example by sending an invalid username without a password.    7.5  High  2017-01-07  2010-04-01  View
49923  CVE-2009-2682  Unspecified vulnerability in Role-Based Access Control (RBAC) in HP HP-UX B.11.23 and B.11.31 allows local users to bypass intended access restrictions via unknown vectors.    7.2  High  2017-01-07  2010-08-21  View
50179  CVE-2009-2960  CuteFlow 2.10.3 and 2.11.0_c does not properly restrict access to pages/edituser.php, which allows remote attackers to modify usernames and passwords via a direct request.    7.5  High  2017-01-07  2009-08-25  View
50435  CVE-2009-3230  The core server component in PostgreSQL 8.4 before 8.4.1, 8.3 before 8.3.8, 8.2 before 8.2.14, 8.1 before 8.1.18, 8.0 before 8.0.22, and 7.4 before 7.4.26 does not use the appropriate privileges for the (1) RESET ROLE and (2) RESET SESSION AUTHORIZATION operations, which allows remote authenticated users to gain privileges. NOTE: this is due to an incomplete fix for CVE-2007-6600.    6.5  Medium  2017-01-07  2016-08-22  View
50691  CVE-2009-3490  GNU Wget before 1.12 does not properly handle a "" character in a domain name in the Common Name field of an X.509 certificate, which allows man-in-the-middle remote attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.    6.8  Medium  2017-01-07  2016-12-07  View

Page 2433 of 17672, showing 5 records out of 88360 total, starting on record 12161, ending on 12165

Actions