NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5041 | CVE-2008-5263 | Multiple stack-based buffer overflows in the mt_codec::getHdrHead function in kernel/kls_hdr/fmt_codec_hdr.cpp in ksquirrel-libs 0.8.0 allow context-dependent attackers to execute arbitrary code via a crafted Radiance RGBE image (aka .hdr file). | 2 | 6.8 | Medium | 2017-01-03 | 2009-02-26 | View | |
5042 | CVE-2008-5264 | Cross-site scripting (XSS) vulnerability in searcher.exe in Tornado Knowledge Retrieval System 4.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the p parameter in a root action. | 2 | 4.3 | Medium | 2017-01-03 | 2009-04-08 | View | |
5043 | CVE-2008-5265 | Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the modulo parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2009-04-14 | View | |
5044 | CVE-2008-5266 | Cross-site scripting (XSS) vulnerability in configuration/httpListenerEdit.jsf in the GlassFish 2 UR2 b04 webadmin interface in Sun Java System Application Server 9.1_01 build b09d-fcs and 9.1_02 build b04-fcs allows remote attackers to inject arbitrary web script or HTML via the name parameter, a different vector than CVE-2008-2751. | 2 | 4.3 | Medium | 2017-01-03 | 2011-04-22 | View | |
5045 | CVE-2008-5267 | SQL injection vulnerability in answer.php in Experts 1.0.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the question_id parameter. | 2 | 6.8 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 1009 of 17672, showing 5 records out of 88360 total, starting on record 5041, ending on 5045