NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
48153  CVE-2009-0838  The crypto pseudo device driver in Sun Solaris 10, and OpenSolaris snv_88 through snv_102, does not properly free memory, which allows local users to cause a denial of service (panic) via unspecified vectors, related to the vmem_hash_delete function.    4.9  Medium  2017-01-07  2010-08-21  View
48665  CVE-2009-1380  Cross-site scripting (XSS) vulnerability in JMX-Console in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2 before 4.2.0.CP08 and 4.3 before 4.3.0.CP07 allows remote attackers to inject arbitrary web script or HTML via the filter parameter, related to the key property and the position of quote and colon characters.    4.3  Medium  2017-01-07  2009-12-16  View
49177  CVE-2009-1912  Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to include and execute arbitrary local .php files via a .. (dot dot) in a language cookie. NOTE: this can be leveraged for SQL injection by including awards.php.    6.8  Medium  2017-01-07  2009-06-05  View
49433  CVE-2009-2171  Mahara 1.1 before 1.1.5 does not apply permission checks when saving a view that contains artefacts, which allows remote authenticated users to read another user"s artefact.    Medium  2017-01-07  2009-06-24  View
49945  CVE-2009-2704  CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a request containing a %00 (encoded null byte).    4.3  Medium  2017-01-07  2009-08-11  View

Page 929 of 17672, showing 5 records out of 88360 total, starting on record 4641, ending on 4645

Actions