NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 47650 | CVE-2009-0318 | Untrusted search path vulnerability in the GObject Python interpreter wrapper in Gnumeric allows local users to execute arbitrary code via a Trojan horse Python file in the current working directory, related to a vulnerability in the PySys_SetArgv function (CVE-2008-5983). | 2 | 6.9 | Medium | 2017-01-07 | 2009-04-16 | View | |
| 47908 | CVE-2009-0579 | Linux-PAM before 1.0.4 does not enforce the minimum password age (MINDAYS) as specified in /etc/shadow, which allows local users to bypass intended security policy and change their passwords sooner than specified. | 2 | 4.6 | Medium | 2017-01-07 | 2009-04-16 | View | |
| 48439 | CVE-2009-1144 | Untrusted search path vulnerability in the Gentoo package of Xpdf before 3.02-r2 allows local users to gain privileges via a Trojan horse xpdfrc file in the current working directory, related to an unset SYSTEM_XPDFRC macro in a Gentoo build process that uses the poppler library. | 2 | 6.9 | Medium | 2017-01-07 | 2009-04-16 | View | |
| 48442 | CVE-2009-1148 | Directory traversal vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to read arbitrary files via directory traversal sequences in the file_path parameter ($filename variable). | 2 | 5 | Medium | 2017-01-07 | 2009-04-16 | View | |
| 48443 | CVE-2009-1149 | CRLF injection vulnerability in bs_disp_as_mime_type.php in the BLOB streaming feature in phpMyAdmin before 3.1.3.1 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via the (1) c_type and possibly (2) file_type parameters. | 2 | 7.5 | High | 2017-01-07 | 2009-04-16 | View |
Page 2985 of 17672, showing 5 records out of 88360 total, starting on record 14921, ending on 14925