NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
47370 | CVE-2009-0021 | NTP 4.2.4 before 4.2.4p5 and 4.2.5 before 4.2.5p150 does not properly check the return value from the OpenSSL EVP_VerifyFinal function, which allows remote attackers to bypass validation of the certificate chain via a malformed SSL/TLS signature for DSA and ECDSA keys, a similar vulnerability to CVE-2008-5077. | 2 | 5 | Medium | 2017-01-07 | 2012-10-30 | View | |
48138 | CVE-2009-0821 | Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print function, as demonstrated by a window.print(window.print()) in the onclick attribute of an INPUT element. | 2 | 5 | Medium | 2017-01-07 | 2009-03-05 | View | |
48394 | CVE-2009-1084 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not properly restrict access to the System Configuration object, which allows remote authenticated administrators and possibly remote attackers to have an unspecified impact by modifying this object. | 2 | 6.4 | Medium | 2017-01-07 | 2009-04-16 | View | |
48906 | CVE-2009-1637 | profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to change the admin e-mail address and password via the email and password parameters. | 2 | 6.4 | Medium | 2017-01-07 | 2009-05-15 | View | |
49162 | CVE-2009-1897 | The tun_chr_poll function in drivers/net/tun.c in the tun subsystem in the Linux kernel 2.6.30 and 2.6.30.1, when the -fno-delete-null-pointer-checks gcc option is omitted, allows local users to gain privileges via vectors involving a NULL pointer dereference and an mmap of /dev/net/tun, a different vulnerability than CVE-2009-1894. | 2 | 6.9 | Medium | 2017-01-07 | 2012-03-19 | View |
Page 392 of 17672, showing 5 records out of 88360 total, starting on record 1956, ending on 1960