NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49204 | CVE-2009-1942 | Cross-site scripting (XSS) vulnerability in the Quiz module 5.x, 6.x-2.x before 6.x-2.2, and 6.x-3.x before 6.x-3.0, a module for Drupal, allows remote authenticated users, with create quizzes or quiz questions access, to inject arbitrary web script or HTML via unspecified vectors. | 2 | 3.5 | Low | 2017-01-07 | 2009-06-08 | View | |
| 49460 | CVE-2009-2198 | Apple GarageBand before 5.1 reconfigures Safari to accept all cookies regardless of domain name, which makes it easier for remote web servers to track users. | 2 | 4.3 | Medium | 2017-01-07 | 2009-08-18 | View | |
| 49716 | CVE-2009-2471 | The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper. | 2 | 10 | High | 2017-01-07 | 2010-08-21 | View | |
| 49972 | CVE-2009-2739 | Cross-site scripting (XSS) vulnerability in FreeNAS before 0.69.2 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | 2 | 4.3 | Medium | 2017-01-07 | 2009-09-02 | View | |
| 50228 | CVE-2009-3011 | Google Chrome 1.0.154.48 and earlier, 2.0.172.28, 2.0.172.37, and 3.0.193.2 Beta does not properly block data: URIs in Refresh headers in HTTP responses, which allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to (1) injecting a Refresh header that contains JavaScript sequences in a data:text/html URI or (2) entering a data:text/html URI with JavaScript sequences when specifying the content of a Refresh header. NOTE: the JavaScript executes outside of the context of the HTTP site. | 2 | 4.3 | Medium | 2017-01-07 | 2009-09-05 | View |
Page 3175 of 17672, showing 5 records out of 88360 total, starting on record 15871, ending on 15875