NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5436 | CVE-2008-5694 | PHP remote file inclusion vulnerability in lib/jpgraph/jpgraph_errhandler.inc.php in Sandbox 1.4.1 might allow remote attackers to execute arbitrary PHP code via unspecified vectors. NOTE: the issue, if any, may be located in Aditus JpGraph rather than Sandbox. If so, then this should not be treated as an issue in Sandbox. | 2 | 10 | High | 2017-01-03 | 2009-01-06 | View | |
5437 | CVE-2008-5695 | wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests to update an option, which allows remote authenticated users with manage_options and upload_files capabilities to execute arbitrary code by uploading a PHP script and adding this script"s pathname to active_plugins. | 2 | 8.5 | High | 2017-01-03 | 2009-01-29 | View | |
5438 | CVE-2008-5696 | Novell NetWare 6.5 before Support Pack 8, when an OES2 Linux server is installed into the NDS tree, does not require a password for the ApacheAdmin console, which allows remote attackers to reconfigure the Apache HTTP Server via console operations. | 2 | 9.3 | High | 2017-01-03 | 2011-03-07 | View | |
5439 | CVE-2008-5697 | The skype_tool.copy_num method in the Skype extension BETA 2.2.0.95 for Firefox allows remote attackers to write arbitrary data to the clipboard via a string argument. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
5440 | CVE-2008-5698 | HTMLTokenizer::scriptHandler in Konqueror in KDE 3.5.9 and 3.5.10 allows remote attackers to cause a denial of service (application crash) via an invalid document.load call that triggers use of a deleted object. NOTE: some of these details are obtained from third party information. | 2 | 4.3 | Medium | 2017-01-03 | 2009-05-09 | View |
Page 1088 of 17672, showing 5 records out of 88360 total, starting on record 5436, ending on 5440