NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 50222 | CVE-2009-3005 | Lunascape 5.1.3 and 5.1.4 allows remote attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary URL on the web site visited by the victim, as demonstrated by a visit to an attacker-controlled web page, which triggers a spoofed login form for the site containing that page. NOTE: a related attack was reported in which an arbitrary file: URL is shown. | 2 | 4.3 | Medium | 2017-01-07 | 2009-09-05 | View | |
| 50478 | CVE-2009-3273 | iPhone Mail in Apple iPhone OS, and iPhone OS for iPod touch, does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof arbitrary SSL e-mail servers via a crafted certificate. | 2 | 7.5 | High | 2017-01-07 | 2009-09-22 | View | |
| 50734 | CVE-2009-3534 | Directory traversal vulnerability in index.php in LionWiki 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-10-05 | View | |
| 50990 | CVE-2009-3822 | PHP remote file inclusion vulnerability in Fiji Web Design Ajax Chat (com_ajaxchat) component 1.0 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[mosConfig_absolute_path] parameter to tests/ajcuser.php. | 2 | 7.5 | High | 2017-01-07 | 2009-10-28 | View | |
| 51246 | CVE-2009-4096 | RADIO istek scripti 2.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain user credentials via a direct request for estafresgaftesantusyan.inc. | 2 | 7.5 | High | 2017-01-07 | 2009-12-02 | View |
Page 2816 of 17672, showing 5 records out of 88360 total, starting on record 14076, ending on 14080