NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
80796 | CVE-2002-1845 | Cross-site scripting (XSS) vulnerability in index.php in Yet Another Bulletin Board (YaBB) 1.40 and 1.41 allows remote attackers to inject arbitrary web script or HTML via the password (passwrd) parameter. | 2 | 4.3 | Medium | 2017-01-05 | 2008-09-05 | View | |
80797 | CVE-2002-1846 | Yet Another Bulletin Board (YaBB) 1.40 and 1.41 does not require a user to submit the correct password before changing it to a new password, which allows remote attackers to modify passwords by stealing the cookie of another user, modifying the expiretime setting, and submitting the change in a profile2 action to index.php. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View | |
80798 | CVE-2002-1847 | Buffer overflow in mplay32.exe of Microsoft Windows Media Player (WMP) 6.3 through 7.1 allows remote attackers to execute arbitrary commands via a long mp3 filename command line argument. NOTE: since the only known attack vector requires command line access, this may not be a vulnerability. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
80799 | CVE-2002-1848 | TightVNC before 1.2.4 running on Windows stores unencrypted passwords in the password text control of the WinVNC Properties dialog, which could allow local users to access passwords. | 2 | 2.1 | Low | 2017-01-05 | 2008-09-05 | View | |
80800 | CVE-2002-1849 | ParaChat Server 4.0 does not log users off if the browser"s back button is used, which allows remote attackers to cause a denial of service by repeatedly logging into a chat room, hitting the back button, then logging into the same chat room as a different user, which fills the chat room with invalid users. | 2 | 5 | Medium | 2017-01-05 | 2008-09-05 | View |
Page 1226 of 17672, showing 5 records out of 88360 total, starting on record 6126, ending on 6130