NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
12303 | CVE-2010-0761 | SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a gamecatalog action. | 2 | 7.5 | High | 2017-01-18 | 2010-03-03 | View | |
77839 | CVE-2001-0366 | saposcol in SAP R/3 Web Application Server Demo before 1.5 trusts the PATH environmental variable to find and execute the expand program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse expand program. | 2 | 7.2 | High | 2017-01-05 | 2008-09-05 | View | |
12559 | CVE-2010-1025 | Cross-site scripting (XSS) vulnerability in the TGM-Newsletter (tgm_newsletter) extension 0.0.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-18 | 2010-03-22 | View | |
78095 | CVE-2001-0630 | Directory traversal vulnerability in MIMAnet viewsrc.cgi 2.0 allows a remote attacker to read arbitrary files via a ".." (dot dot) attack in the "loc" variable. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
12815 | CVE-2010-1283 | Adobe Shockwave Player before 11.5.7.609 does not properly parse 3D objects in .dir (aka Director) files, which allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a modified field in a 0xFFFFFF49 record. | 2 | 9.3 | High | 2017-01-18 | 2010-08-21 | View |
Page 1039 of 17672, showing 5 records out of 88360 total, starting on record 5191, ending on 5195