NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 48694 | CVE-2009-1418 | Cross-site scripting (XSS) vulnerability in HP System Management Homepage (SMH) before 3.0.1.73 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-07 | 2012-03-23 | View | |
| 48950 | CVE-2009-1681 | WebKit in Apple Safari before 4.0, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 does not prevent web sites from loading third-party content into a subframe, which allows remote attackers to bypass the Same Origin Policy and conduct "clickjacking" attacks via a crafted HTML document. | 2 | 4.3 | Medium | 2017-01-07 | 2011-02-17 | View | |
| 49206 | CVE-2009-1944 | Stack-based buffer overflow in AIMP 2.51 build 330 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag. | 2 | 9.3 | High | 2017-01-07 | 2009-06-08 | View | |
| 49462 | CVE-2009-2200 | WebKit in Apple Safari before 4.0.3 does not properly restrict the URL scheme of the pluginspage attribute of an EMBED element, which allows user-assisted remote attackers to launch arbitrary file: URLs and obtain sensitive information via a crafted HTML document. | 2 | 7.1 | High | 2017-01-07 | 2011-02-17 | View | |
| 49718 | CVE-2009-2473 | neon before 0.28.6, when expat is used, does not properly detect recursion during entity expansion, which allows context-dependent attackers to cause a denial of service (memory and CPU consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564. | 2 | 4.3 | Medium | 2017-01-07 | 2013-02-06 | View |
Page 3296 of 17672, showing 5 records out of 88360 total, starting on record 16476, ending on 16480