NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48384 | CVE-2009-1074 | Sun Java System Identity Manager (IdM) 7.0 through 8.0 does not use SSL in all expected circumstances, which makes it easier for remote attackers to obtain sensitive information by sniffing the network, related to "ssl termination devices" and lack of support for relative URLs. | 2 | 5 | Medium | 2017-01-07 | 2009-10-06 | View | |
48640 | CVE-2009-1354 | Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the URI. | 2 | 4 | Medium | 2017-01-07 | 2009-04-21 | View | |
48896 | CVE-2009-1627 | Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbitrary code via a long .asf URL in the HREF attribute of a REF element in a .asx file. | 2 | 9.3 | High | 2017-01-07 | 2009-05-13 | View | |
49152 | CVE-2009-1887 | agent/snmp_agent.c in snmpd in net-snmp 5.0.9 in Red Hat Enterprise Linux (RHEL) 3 allows remote attackers to cause a denial of service (daemon crash) via a crafted SNMP GETBULK request that triggers a divide-by-zero error. NOTE: this vulnerability exists because of an incorrect fix for CVE-2008-4309. | 2 | 5 | Medium | 2017-01-07 | 2010-08-21 | View | |
49408 | CVE-2009-2146 | Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka SugarCRM) before 5.2f allows remote authenticated users to execute arbitrary code by uploading a file with only an extension in its name, then accessing the file via a direct request to a modified filename under cache/modules/Emails/, as demonstrated using .php as the entire original name. | 2 | 6 | Medium | 2017-01-07 | 2009-06-25 | View |
Page 55 of 17672, showing 5 records out of 88360 total, starting on record 271, ending on 275