NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
47817  CVE-2009-0485  Cross-site request forgery (CSRF) vulnerability in Bugzilla 2.17 to 2.22.7, 3.0 before 3.0.7, 3.2 before 3.2.1, and 3.3 before 3.3.2 allows remote attackers to delete unused flag types via a link or IMG tag to editflagtypes.cgi.    5.8  Medium  2017-01-07  2009-03-25  View
47818  CVE-2009-0486  Bugzilla 3.2.1, 3.0.7, and 3.3.2, when running under mod_perl, calls the srand function at startup time, which causes Apache children to have the same seed and produce insufficiently random numbers for random tokens, which allows remote attackers to bypass cross-site request forgery (CSRF) protection mechanisms and conduct unauthorized activities as other users.    7.5  High  2017-01-07  2009-03-25  View
48364  CVE-2009-1054  Unspecified vulnerability in JustSystems Ichitaro 13, 2004 through 2008, Lite2, and Ichitaro viewer 5.1.5.0 and earlier allows remote attackers to execute arbitrary code via a crafted file, as exploited in the wild by Trojan.Tarodrop.H in March 2009.    9.3  High  2017-01-07  2009-03-25  View
3834  CVE-2008-3972  pkcs15-tool in OpenSC before 0.11.6 does not apply security updates to a smart card unless the card"s label matches the "OpenSC" string, which might allow physically proximate attackers to exploit vulnerabilities that the card owner expected were patched, as demonstrated by exploitation of CVE-2008-2235.    6.6  Medium  2017-01-03  2009-03-25  View
CVE-2008-0004  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.        2017-01-03  2009-03-26  View

Page 2894 of 17672, showing 5 records out of 88360 total, starting on record 14466, ending on 14470

Actions