NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49322  CVE-2009-2060  src/net/http/http_transaction_winhttp.cc in Google Chrome before 1.0.154.53 uses the HTTP Host header to determine the context of a document provided in a (1) 4xx or (2) 5xx CONNECT response from a proxy server, which allows man-in-the-middle attackers to execute arbitrary web script by modifying this CONNECT response, aka an "SSL tampering" attack.    5.8  Medium  2017-01-07  2009-06-23  View
49323  CVE-2009-2061  Mozilla Firefox before 3.0.10 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site"s context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.    9.3  High  2017-01-07  2009-06-23  View
49324  CVE-2009-2062  Apple Safari before 3.2.2 processes a 3xx HTTP CONNECT response before a successful SSL handshake, which allows man-in-the-middle attackers to execute arbitrary web script, in an https site"s context, by modifying this CONNECT response to specify a 302 redirect to an arbitrary https web site.    6.8  Medium  2017-01-07  2009-06-23  View
48048  CVE-2009-0729  Multiple directory traversal vulnerabilities in Page Engine CMS 2.0 Basic and Pro allow remote attackers to include and execute arbitrary local files via directory traversal sequences in the fPrefix parameter to (1) modules/recent_poll_include.php, (2) modules/login_include.php, and (3) modules/statistics_include.php and (4) configuration.inc.php in includes/. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.    6.8  Medium  2017-01-07  2009-06-23  View
48049  CVE-2009-0730  Multiple SQL injection vulnerabilities in the GigCalendar (com_gigcal) component 1.0 for Mambo and Joomla!, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via (1) the gigcal _venues_id parameter in a details action to index.php, which is not properly handled by venuedetails.php, and (2) the gigcal_bands_id parameter in a details action to index.php, which is not properly handled by banddetails.php, different vectors than CVE-2009-0726.    6.8  Medium  2017-01-07  2009-06-23  View

Page 3159 of 17672, showing 5 records out of 88360 total, starting on record 15791, ending on 15795

Actions