NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
49931 | CVE-2009-2690 | The encoder in Sun Java SE 6 before Update 15, and OpenJDK, grants read access to private variables with unspecified names, which allows context-dependent attackers to obtain sensitive information via an untrusted (1) applet or (2) application. | 2 | 5 | Medium | 2017-01-07 | 2010-08-21 | View | |
50187 | CVE-2009-2968 | Directory traversal vulnerability in a support component in the web interface in VMware Studio 2.0 public beta before build 1017-185256 allows remote attackers to upload files to arbitrary locations via unspecified vectors. | 2 | 5 | Medium | 2017-01-07 | 2010-07-22 | View | |
50443 | CVE-2009-3238 | The get_random_int function in drivers/char/random.c in the Linux kernel before 2.6.30 produces insufficiently random numbers, which allows attackers to predict the return value, and possibly defeat protection mechanisms based on randomization, via vectors that leverage the function"s tendency to "return the same value over and over again for long stretches of time." | 2 | 7.8 | High | 2017-01-07 | 2012-03-19 | View | |
50699 | CVE-2009-3498 | SQL injection vulnerability in php/update_article_hits.php in HBcms 1.7 allows remote attackers to execute arbitrary SQL commands via the article_id parameter. | 2 | 6.8 | Medium | 2017-01-07 | 2009-10-01 | View | |
50955 | CVE-2009-3786 | Cross-site scripting (XSS) vulnerability in Organic Groups (OG) Vocabulary 5.x before 5.x-1.1 and 6.x before 6.x-1.1, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via the group title. | 2 | 4.3 | Medium | 2017-01-07 | 2009-11-11 | View |
Page 707 of 17672, showing 5 records out of 88360 total, starting on record 3531, ending on 3535