NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
50436 | CVE-2009-3231 | The core server component in PostgreSQL 8.3 before 8.3.8 and 8.2 before 8.2.14, when using LDAP authentication with anonymous binds, allows remote attackers to bypass authentication via an empty password. | 2 | 6.8 | Medium | 2017-01-07 | 2016-08-22 | View | |
50692 | CVE-2009-3491 | SQL injection vulnerability in the Kinfusion SportFusion (com_sportfusion) component 0.2.2 through 0.2.3 for Joomla! allows remote attackers to execute arbitrary SQL commands via the cid[0] parameter in a teamdetail action to index.php. | 2 | 7.5 | High | 2017-01-07 | 2009-10-02 | View | |
50948 | CVE-2009-3779 | Cross-site scripting (XSS) vulnerability in vCard 5.x before 5.x-1.4 and 6.x before 6.x-1.3, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to the addition of the theme_vcard function to a theme and the use of default content. | 2 | 4.3 | Medium | 2017-01-07 | 2009-10-27 | View | |
51204 | CVE-2009-4052 | Multiple cross-site scripting (XSS) vulnerabilities in the JSF Widget Library Runtime in IBM Rational Application Developer for WebSphere Software before 7.0.0.10 and Rational Software Architect before 7.0.0.10 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) the JSF Tree Control and (2) the JavaScript Resource Servlet. | 2 | 4.3 | Medium | 2017-01-07 | 2009-11-23 | View | |
51460 | CVE-2009-4337 | SQL injection vulnerability in the Diocese of Portsmouth Calendar (pd_calendar) extension 0.4.1 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors, a different issue than CVE-2008-6691. | 2 | 7.5 | High | 2017-01-07 | 2009-12-18 | View |
Page 290 of 17672, showing 5 records out of 88360 total, starting on record 1446, ending on 1450