NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
48141 | CVE-2009-0826 | BlogHelper stores common_db.inc under the web root with insufficient access control, which allows remote attackers to download the database file containing user credentials via a direct request. | 2 | 5 | Medium | 2017-01-07 | 2009-03-06 | View | |
48397 | CVE-2009-1087 | Multiple argument injection vulnerabilities in PPLive.exe in PPLive 1.9.21 and earlier allow remote attackers to execute arbitrary code via a UNC share pathname in the LoadModule argument to the (1) synacast, (2) Play, (3) pplsv, or (4) ppvod URI handler. NOTE: some of these details are obtained from third party information. | 2 | 9.3 | High | 2017-01-07 | 2009-07-21 | View | |
48653 | CVE-2009-1368 | Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in the page parameter. NOTE: this might be the same issue as CVE-2008-6126.2, which may have been fixed in 1.10.3. | 2 | 7.5 | High | 2017-01-07 | 2009-04-23 | View | |
48909 | CVE-2009-1640 | Stack-based buffer overflow in Nucleus Data Recovery Kernel Recovery for Macintosh 4.04 allows user-assisted attackers to execute arbitrary code via a crafted .AMHH file. | 2 | 9.3 | High | 2017-01-07 | 2009-05-18 | View | |
49165 | CVE-2009-1900 | The Configservice APIs in the Administrative Console component in IBM WebSphere Application Server (WAS) 6.0.2 before 6.0.2.35, 6.1 before 6.1.0.25, and 7.0 before 7.0.0.5, when tracing is enabled, allow remote attackers to obtain sensitive information via unspecified use of the wsadmin scripting tool. | 2 | 5 | Medium | 2017-01-07 | 2009-08-15 | View |
Page 938 of 17672, showing 5 records out of 88360 total, starting on record 4686, ending on 4690