NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
80601 | CVE-2002-1648 | Cross-site request forgery (CSRF) vulnerability in compose.php in SquirrelMail before 1.2.3 allows remote attackers to send email as other users via an IMG URL with modified send_to and subject parameters. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
84185 | CVE-2017-0565 | An elevation of privilege vulnerability in the MediaTek thermal driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-28175904. References: M-ALPS02696516. | 2 | 7.6 | High | 2017-07-18 | 2017-07-10 | View | |
84697 | CVE-2017-5656 | Apache CXF's STSClient before 3.1.11 and 3.0.13 uses a flawed way of caching tokens that are associated with delegation tokens, which means that an attacker could craft a token which would return an identifer corresponding to a cached token for another user. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
66010 | CVE-2005-0246 | The intagg contrib module for PostgreSQL 8.0.0 and earlier allows attackers to cause a denial of service (crash) via crafted arrays. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
66778 | CVE-2005-1029 | Multiple SQL injection vulnerabilities in Active Auction House allow remote attackers to execute arbitrary SQL commands via the (1) catid, (2) SortDir, or (3) Sortby parameter to default.asp, (4) itemID parameter to ItemInfo.asp, or (5) Email field to sendpassword.asp. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View |
Page 1080 of 17672, showing 5 records out of 88360 total, starting on record 5396, ending on 5400