NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 2556 | CVE-2008-2650 | Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the sl parameter to index.php. NOTE: this can be leveraged for remote file execution by including adm.php and then invoking the upload action. NOTE: on 20080601, the vendor patched 3.1 without changing the version number. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-14 | View | |
| 2558 | CVE-2008-2652 | Multiple SQL injection vulnerabilities in catalog.php in SMEWeb 1.4b and 1.4f allow remote attackers to execute arbitrary SQL commands via the (1) idp and (2) category parameters. | 2 | 7.5 | High | 2017-01-03 | 2009-04-14 | View | |
| 48007 | CVE-2009-0681 | PGP Desktop before 9.10 allows local users to (1) cause a denial of service (crash) via a crafted IOCTL request to pgpdisk.sys, and (2) cause a denial of service (crash) and execute arbitrary code via a crafted IRP in an IOCTL request to pgpwded.sys. | 2 | 7.2 | High | 2017-01-07 | 2009-04-15 | View | |
| 48394 | CVE-2009-1084 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying this object. | 2 | 6.4 | Medium | 2017-01-07 | 2009-04-16 | View | |
| 4639 | CVE-2008-4825 | Multiple buffer overflows in UltraISO 9.3.1.2633, and possibly other versions before 9.3.3.2685, allow user-assisted attackers to execute arbitrary code via a crafted (1) CIF, (2) C2D, or (3) GI file. | 2 | 9.3 | High | 2017-01-03 | 2009-04-16 | View |
Page 2984 of 17672, showing 5 records out of 88360 total, starting on record 14916, ending on 14920