NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49442 | CVE-2009-2180 | Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) absolute path in the file parameter. | 2 | 5 | Medium | 2017-01-07 | 2013-08-07 | View | |
| 49698 | CVE-2009-2453 | Citrix XenApp (formerly Presentation Server) 4.5 Hotfix Rollup Pack 3 does not apply an access policy when it is defined with the Access Gateway Advanced Edition filters, which allows attackers to bypass intended access restrictions via unknown vectors. | 2 | 7.5 | High | 2017-01-07 | 2009-07-14 | View | |
| 49954 | CVE-2009-2717 | The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on Windows 2000 Professional does not provide a Security Warning Icon, which makes it easier for context-dependent attackers to trick a user into interacting unsafely with an untrusted applet. | 2 | 6.8 | Medium | 2017-01-07 | 2009-08-11 | View | |
| 50210 | CVE-2009-2993 | The JavaScript for Acrobat API in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 does not properly implement the (1) Privileged Context and (2) Safe Path restrictions for unspecified JavaScript methods, which allows remote attackers to create arbitrary files, and possibly execute arbitrary code, via the cPath parameter in a crafted PDF file. NOTE: some of these details are obtained from third party information. | 2 | 9.3 | High | 2017-01-07 | 2010-08-21 | View | |
| 50466 | CVE-2009-3261 | update/update_0.1.2_to_0.2.php in LiveStreet 0.2 does not require administrative authentication, which allows remote attackers to perform DROP TABLE operations via unspecified vectors. | 2 | 7.5 | High | 2017-01-07 | 2009-09-22 | View |
Page 2713 of 17672, showing 5 records out of 88360 total, starting on record 13561, ending on 13565