NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
47446  CVE-2009-0106  SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbitrary SQL commands via the user_id parameter.    7.5  High  2017-01-07  2009-04-10  View
48513  CVE-2009-1226  core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions, which allows remote attackers to delete arbitrary files via the file parameter.    7.5  High  2017-01-07  2009-04-10  View
48517  CVE-2009-1230  Static code injection vulnerability in index.php in Podcast Generator 1.1 and earlier allows remote authenticated administrators to inject arbitrary PHP code into config.php via the recent parameter in a config change action.    6.5  Medium  2017-01-07  2009-04-10  View
48009  CVE-2009-0686  The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Security Pro 2008 and 2009, allows local users to gain privileges via a crafted IRP in a METHOD_NEITHER IOCTL request to Device mactmon that overwrites memory.    7.2  High  2017-01-07  2009-04-10  View
47534  CVE-2009-0197  Integer overflow in the FORMATS Plugin before 4.23 for IrfanView allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a large XPM file that triggers a heap-based buffer overflow.    9.3  High  2017-01-07  2009-04-10  View

Page 2964 of 17672, showing 5 records out of 88360 total, starting on record 14816, ending on 14820

Actions