NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48153 | CVE-2009-0838 | The crypto pseudo device driver in Sun Solaris 10, and OpenSolaris snv_88 through snv_102, does not properly free memory, which allows local users to cause a denial of service (panic) via unspecified vectors, related to the vmem_hash_delete function. | 2 | 4.9 | Medium | 2017-01-07 | 2010-08-21 | View | |
48665 | CVE-2009-1380 | Cross-site scripting (XSS) vulnerability in JMX-Console in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 allows remote attackers to inject arbitrary web script or HTML via the filter parameter, related to the key property and the position of quote and colon characters. | 2 | 4.3 | Medium | 2017-01-07 | 2009-12-16 | View | |
49177 | CVE-2009-1912 | Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php. | 2 | 6.8 | Medium | 2017-01-07 | 2009-06-05 | View | |
49433 | CVE-2009-2171 | Mahara 1.1 before 1.1.5 does not apply permission checks when saving a view that contains artefacts, which allows remote authenticated users to read another user"s artefact. | 2 | 4 | Medium | 2017-01-07 | 2009-06-24 | View | |
49945 | CVE-2009-2704 | CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing a %00 (encoded null byte). | 2 | 4.3 | Medium | 2017-01-07 | 2009-08-11 | View |
Page 929 of 17672, showing 5 records out of 88360 total, starting on record 4641, ending on 4645