NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
59412 | CVE-2006-0681 | Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute arbitrary code via format string specifiers in the WHATIDO variable. | 2 | 7.5 | High | 2016-12-20 | 2011-03-07 | View | |
59668 | CVE-2006-0941 | Multiple cross-site scripting (XSS) vulnerabilities in post.php in ShoutLIVE 1.1.0 allow remote attackers to inject arbitrary web script or HTML via certain variables when posting new messages. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
59924 | CVE-2006-1210 | The web interface for IBM Tivoli Micromuse Netcool/NeuSecure 3.0.236 includes the MySQL database username and password in cleartext in body.phtml, which allows remote attackers to gain privileges by reading the source. NOTE: IBM has privately confirmed to CVE that a fix is available for these issues. | 2 | 7.5 | High | 2016-12-20 | 2008-09-05 | View | |
60180 | CVE-2006-1471 | Format string vulnerability in the CF_syslog function launchd in Apple Mac OS X 10.4 up to 10.4.6 allows local users to execute arbitrary code via format string specifiers that are not properly handled in a syslog call in the logging facility, as demonstrated by using a crafted plist file. | 2 | 4.6 | Medium | 2016-12-20 | 2011-03-07 | View | |
60436 | CVE-2006-1731 | Mozilla Firefox and Thunderbird 1.x before 1.5 and 1.0.x before 1.0.8, Mozilla Suite before 1.7.13, and SeaMonkey before 1.0 returns the Object class prototype instead of the global window object when (1) .valueOf.call or (2) .valueOf.apply are called without any arguments, which allows remote attackers to conduct cross-site scripting (XSS) attacks. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 1253 of 17672, showing 5 records out of 88360 total, starting on record 6261, ending on 6265