NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
50438 | CVE-2009-3233 | changetrack 4.3 allows local users to execute arbitrary commands via CRLF sequences and shell metacharacters in a filename in a directory that is checked by changetrack. | 2 | 7.2 | High | 2017-01-07 | 2009-09-17 | View | |
50950 | CVE-2009-3781 | The filefield_file_download function in FileField 6.x-3.1, a module for Drupal, does not properly check node-access permissions for Drupal core private files, which allows remote attackers to access unauthorized files via unspecified vectors. | 2 | 7.5 | High | 2017-01-07 | 2009-10-27 | View | |
51462 | CVE-2009-4339 | SQL injection vulnerability in the Subscription (mf_subscription) extension 0.2.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unknown vectors. | 2 | 7.5 | High | 2017-01-07 | 2010-06-29 | View | |
52742 | CVE-2007-0518 | Scriptsez Smart PHP Subscriber (aka subscribe) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain encoded passwords via a direct request for pwd.txt. | 2 | 7.5 | High | 2017-01-07 | 2008-11-13 | View | |
53510 | CVE-2007-1320 | Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow. | 2 | 7.2 | High | 2017-01-07 | 2012-11-05 | View |
Page 529 of 17672, showing 5 records out of 88360 total, starting on record 2641, ending on 2645