NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48869  CVE-2009-1600  Apple Safari executes DOM calls in response to a javascript: URI in the target attribute of a submit element within a form contained in an inline PDF file, which might allow remote attackers to bypass intended Adobe Acrobat JavaScript restrictions on accessing the document object, as demonstrated by a web site that permits PDF uploads by untrusted users, and therefore has a shared document.domain between the web site and this javascript: URI. NOTE: the researcher reports that Adobe"s position is "a PDF file is active content."    9.3  High  2017-01-07  2009-05-14  View
5355  CVE-2008-5606  Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for qmail.mdb.    Medium  2017-01-03  2009-05-14  View
5359  CVE-2008-5616  Stack-based buffer overflow in the demux_open_vqf function in libmpdemux/demux_vqf.c in MPlayer 1.0 rc2 before r28150 allows remote attackers to execute arbitrary code via a malformed TwinVQ file.    10  High  2017-01-03  2009-05-14  View
5360  CVE-2008-5617  The ACL handling in rsyslog 3.12.1 to 3.20.0, 4.1.0, and 4.1.1 does not follow $AllowedSender directive, which allows remote attackers to bypass intended access restrictions and spoof log messages or create a large number of spurious messages.    8.5  High  2017-01-03  2009-05-14  View
48626  CVE-2009-1339  Cross-site request forgery (CSRF) vulnerability in TWiki before 4.3.1 allows remote authenticated users to hijack the authentication of arbitrary users for requests that update pages, as demonstrated by a URL for a save script in the SRC attribute of an IMG element, a related issue to CVE-2009-1434.    Medium  2017-01-07  2009-05-14  View

Page 3066 of 17672, showing 5 records out of 88360 total, starting on record 15326, ending on 15330

Actions