NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
54283  CVE-2007-2113  SQL injection vulnerability in the Upgrade/Downgrade component (DBMS_UPGRADE_INTERNAL) for Oracle Database 10.1.0.5 allows remote authenticated users to execute arbitrary SQL commands via unknown vectors, aka DB07. NOTE: as of 20070424, Oracle has not disputed reliable claims that DB07 is actually for multiple issues.    7.5  High  2017-01-07  2012-10-22  View
54539  CVE-2007-2372  admin/send_mod.php in Gregory Kokanosky phpMyNewsletter 0.8 beta5 and earlier prints a Location header but does not exit when administrative credentials are missing, which allows remote attackers to compose an e-mail message via a post with the subject, message, format, and list_id fields; and send the message via a direct request for the MsgId value under admin/.    10  High  2017-01-07  2008-09-05  View
54795  CVE-2007-2631  Cross-site request forgery (CSRF) vulnerability in SquirrelMail 1.4.8-4.fc6 and earlier allows remote attackers to perform unspecified actions as arbitrary users via unspecified vectors. NOTE: this issue might overlap CVE-2007-2589 or CVE-2002-1648.    7.5  High  2017-01-07  2008-11-15  View
55051  CVE-2007-2891  Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) bank_data[root] parameter to modules/bank/includes/design/main.inc.php, or the (2) fm_data[root] parameter to (a) includes/config/master.inc.php or (b) includes/functions/master.inc.php.    7.5  High  2017-01-07  2011-03-07  View
55307  CVE-2007-3153  The ares_init:randomize_key function in c-ares, on platforms other than Windows, uses a weak facility for producing a random number sequence (Unix rand), which makes it easier for remote attackers to spoof DNS responses by guessing certain values.    Medium  2017-01-07  2012-10-30  View

Page 1158 of 17672, showing 5 records out of 88360 total, starting on record 5786, ending on 5790

Actions