NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
4898 | CVE-2008-5114 | Multiple cross-site scripting (XSS) vulnerabilities in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 2 | 4.3 | Medium | 2017-01-03 | 2012-10-30 | View | |
70434 | CVE-2005-4845 | The Java Plug-in 1.4.2_03 and 1.4.2_04 controls, and the 1.4.2_03 and 1.4.2_04 <applet> redirector controls, allow remote attackers to cause a denial of service (Internet Explorer crash) by creating a COM object of the class associated with the control"s CLSID, which is not intended for use within Internet Explorer. | 2 | 5 | Medium | 2017-01-03 | 2009-08-28 | View | |
5154 | CVE-2008-5376 | editcomment in crip 3.7 allows local users to overwrite arbitrary files via a symlink attack on a /tmp/*.tag.tmp temporary file. | 2 | 6.9 | Medium | 2017-01-03 | 2008-12-09 | View | |
5410 | CVE-2008-5668 | Multiple cross-site scripting (XSS) vulnerabilities in Textpattern (aka Txp CMS) 4.0.5 allow remote attackers to inject arbitrary web script or HTML via (1) the PATH_INFO to setup/index.php or (2) the name parameter to index.php in the comments preview section. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
5666 | CVE-2008-5935 | Facto stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for database/facto.mdb. NOTE: some of these details are obtained from third party information. | 2 | 5 | Medium | 2017-01-03 | 2009-01-29 | View |
Page 1234 of 17672, showing 5 records out of 88360 total, starting on record 6166, ending on 6170