NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5139 | CVE-2008-5361 | The ActionScript 2 virtual machine in Adobe Flash Player 10.x before 10.0.12.36 and 9.x before 9.0.151.0, and Adobe AIR before 1.5, does not verify a member element"s size when performing (1) DefineConstantPool, (2) ActionJump, (3) ActionPush, (4) ActionTry, and unspecified other actions, which allows remote attackers to read sensitive data from process memory via a crafted PDF file. | 2 | 4.3 | Medium | 2017-01-03 | 2009-03-20 | View | |
5395 | CVE-2008-5653 | SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary SQL commands via the rsargs parameter, as reachable through the username parameter. NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-03 | 2008-12-24 | View | |
5651 | CVE-2008-5920 | The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a crafted username that is processed by the preg_replace function with the eval switch. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View | |
6419 | CVE-2008-6688 | Cross-site scripting (XSS) vulnerability in JobControl (dmmjobcontrol) 1.15.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2009-08-15 | View | |
6675 | CVE-2008-6944 | Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension as a profile logo, then accessing it via a direct request to the file in cars_images/. | 2 | 6.5 | Medium | 2017-01-03 | 2009-08-15 | View |
Page 1146 of 17672, showing 5 records out of 88360 total, starting on record 5726, ending on 5730