NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
5791 | CVE-2008-6060 | Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by InfoSoft FusionCharts allows remote attackers to inject arbitrary additional SWF content via a URL in the SRC attribute of an IMG element in the dataURL parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
5792 | CVE-2008-6061 | Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) controller files created by Techsmith Camtasia Studio before 5 allows remote attackers to inject arbitrary additional SWF content via a URL in the csPreloader parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
5793 | CVE-2008-6062 | Cross-site scripting (XSS) vulnerability in ActionScript in arbitrary Shockwave Flash (SWF) files created by Adobe Dreamweaver, when the Insert Flash Video feature is used, allows remote attackers to inject arbitrary web script or HTML via an asfunction: URI in the skinName parameter. NOTE: this may overlap CVE-2007-6242, CVE-2007-6244, or CVE-2007-6637. | 2 | 4.3 | Medium | 2017-01-03 | 2009-02-05 | View | |
5794 | CVE-2008-6063 | Microsoft Word 2007, when the "Save as PDF" add-on is enabled, places an absolute pathname in the Subject field during an "Email as PDF" operation, which allows remote attackers to obtain sensitive information such as the sender"s account name and a Temporary Internet Files subdirectory name. | 2 | 4.3 | Medium | 2017-01-03 | 2009-02-05 | View | |
5795 | CVE-2008-6064 | Multiple SQL injection vulnerabilities in DomPHP 0.81 allow remote attackers to execute arbitrary SQL commands via the cat parameter to agenda/index.php, and unspecified other vectors. | 2 | 7.5 | High | 2017-01-03 | 2009-02-05 | View |
Page 1159 of 17672, showing 5 records out of 88360 total, starting on record 5791, ending on 5795