NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67873 | CVE-2005-2169 | Directory traversal vulnerability in source.php in Quick & Dirty PHPSource Printer 1.1 and earlier allows remote attackers to read arbitrary files via ".../...//" sequences in the file parameter, which are reduced to "../" when PHPSource Printer uses a regular expression to remove "../" sequences. | 2 | 5 | Medium | 2017-01-03 | 2008-09-05 | View | |
68129 | CVE-2005-2438 | Cross-site scripting (XSS) vulnerability in UseBB 0.5.1 and earlier allows remote attackers to inject arbitrary Javascript via the BBCode color value. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-10 | View | |
2849 | CVE-2008-2955 | Pidgin 2.4.1 allows remote attackers to cause a denial of service (crash) via a long filename that contains certain characters, as demonstrated using an MSN message that triggers the crash in the msn_slplink_process_msg function. | 2 | 4.3 | Medium | 2017-01-03 | 2013-11-02 | View | |
68385 | CVE-2005-2696 | IBM Lotus Notes does not properly restrict access to password hashes in the Notes Address Book (NAB), which allows remote attackers to obtain sensitive information via the (1) password digest field in the Administration tab of a Lotus Notes client, (2) "PasswordDigest" and "HTTPPassword" fields in the document properties in the NAB, or (3) a direct query to the Domino LDAP server, a different vulnerability than CVE-2005-2428. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View | |
3105 | CVE-2008-3222 | Session fixation vulnerability in Drupal 5.x before 5.9 and 6.x before 6.3, when contributed modules "terminate the current request during a login event," allows remote attackers to hijack web sessions via unknown vectors. | 2 | 6.8 | Medium | 2017-01-03 | 2009-08-19 | View |
Page 1193 of 17672, showing 5 records out of 88360 total, starting on record 5961, ending on 5965