NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49621 | CVE-2009-2374 | Drupal 5.x before 5.19 and 6.x before 6.13 does not properly sanitize failed login attempts for pages that contain a sortable table, which includes the username and password in links that can be read from (1) the HTTP referer header of external web sites that are visited from those links or (2) when page caching is enabled, the Drupal page cache. | 2 | 5 | Medium | 2017-01-07 | 2009-07-08 | View | |
| 49622 | CVE-2009-2375 | Stack-based buffer overflow in Photo DVD Maker 8.02, and possibly earlier versions, allows remote attackers to execute arbitrary code via a long File_Name parameter in a .pdm file. NOTE: some of these details are obtained from third party information. | 2 | 9.3 | High | 2017-01-07 | 2009-07-08 | View | |
| 49623 | CVE-2009-2376 | Cross-site scripting (XSS) vulnerability in the Html::textarea function in application/libraries/Html.php in TangoCMS 2.x before 2.3.0 allows remote attackers to inject arbitrary web script or HTML via the value parameter, related to the Contact module. | 2 | 4.3 | Medium | 2017-01-07 | 2009-07-08 | View | |
| 49624 | CVE-2009-2377 | Buffer overflow in the Avax Vector ActiveX control in avPreview.ocx in AVAX-software Avax Vector ActiveX 1.3 allows remote attackers to cause a denial of service (application crash) via a long PrinterName property. | 2 | 4.3 | Medium | 2017-01-07 | 2009-07-08 | View | |
| 49625 | CVE-2009-2378 | PHP remote file inclusion vulnerability in formmailer.admin.inc.php in Jax FormMailer 3.0.0 allows remote attackers to execute arbitrary PHP code via a URL in the BASE_DIR[jax_formmailer] parameter. | 2 | 7.5 | High | 2017-01-07 | 2009-07-08 | View |
Page 3202 of 17672, showing 5 records out of 88360 total, starting on record 16006, ending on 16010