NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 49946 | CVE-2009-2705 | CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing non-canonical, "overlong Unicode" in place of blacklisted characters. | 2 | 4.3 | Medium | 2017-01-07 | 2009-08-11 | View | |
| 49954 | CVE-2009-2717 | The Abstract Window Toolkit (AWT) implementation in Sun Java SE 6 before Update 15 on Windows 2000 Professional does not provide a Security Warning Icon, which makes it easier for context-dependent attackers to trick a user into interacting unsafely with an untrusted applet. | 2 | 6.8 | Medium | 2017-01-07 | 2009-08-11 | View | |
| 49963 | CVE-2009-2727 | Stack-based buffer overflow in the _tt_internal_realpath function in the ToolTalk library (libtt.a) in IBM AIX 5.2.0, 5.3.0, 5.3.7 through 5.3.10, and 6.1.0 through 6.1.3, when the rpc.ttdbserver daemon is enabled in /etc/inetd.conf, allows remote attackers to execute arbitrary code via a long XDR-encoded ASCII string to remote procedure 15. | 2 | 9.3 | High | 2017-01-07 | 2009-08-11 | View | |
| 49968 | CVE-2009-2735 | SQL injection vulnerability in admin.php in sun-jester OpenNews 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-08-11 | View | |
| 49969 | CVE-2009-2736 | Static code injection vulnerability in admin.php in sun-jester OpenNews 1.0 allows remote authenticated administrators to inject arbitrary PHP code into config.php via the "Overall Width" field in a setconfig action. | 2 | 6.5 | Medium | 2017-01-07 | 2009-08-11 | View |
Page 3277 of 17672, showing 5 records out of 88360 total, starting on record 16381, ending on 16385