NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
49685  CVE-2009-2440  Cross-site scripting (XSS) vulnerability in index.php in JNM Guestbook 3.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter.    4.3  Medium  2017-01-07  2009-07-13  View
49941  CVE-2009-2700  src/network/ssl/qsslcertificate.cpp in Nokia Trolltech Qt 4.x does not properly handle a "" character in a domain name in the Subject Alternative Name field of an X.509 certificate, which allows man-in-the-middle attackers to spoof arbitrary SSL servers via a crafted certificate issued by a legitimate Certification Authority, a related issue to CVE-2009-2408.    4.3  Medium  2017-01-07  2013-02-07  View
50453  CVE-2009-3248  Cross-site request forgery (CSRF) vulnerability in the RSS module in vtiger CRM 5.0.4 allows remote attackers to hijack the authentication of Admin users for requests that modify the news feed system via the rssurl parameter in a Save action to index.php.    6.8  Medium  2017-01-07  2009-09-21  View
50709  CVE-2009-3508  Multiple directory traversal vulnerabilities in MUJE CMS 1.0.4.34 allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) _class parameter to admin.php and the (2) url parameter to install/install.php; and allow remote authenticated administrators to read arbitrary files via a .. (dot dot) in the (3) _htmlfile parameter to admin.php.    Medium  2017-01-07  2009-10-01  View
51221  CVE-2009-4071  Opera before 10.10, when exception stacktraces are enabled, places scripting error messages from a web site into variables that can be read by a different web site, which allows remote attackers to obtain sensitive information or conduct cross-site scripting (XSS) attacks via unspecified vectors.    5.8  Medium  2017-01-07  2010-08-21  View

Page 785 of 17672, showing 5 records out of 88360 total, starting on record 3921, ending on 3925

Actions