NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
4387 | CVE-2008-4571 | Cross-site scripting (XSS) vulnerability in the LiveSearch module in Plone before 3.0.4 allows remote attackers to inject arbitrary web script or HTML via the Description field for search results, as demonstrated using the onerror Javascript even in an IMG tag. | 2 | 4.3 | Medium | 2017-01-03 | 2008-11-15 | View | |
70179 | CVE-2005-4590 | Spb Kiosk Engine 1.0.0.1 allows local users to bypass restrictions on allowed applications via (1) removable media containing a program that will execute because of the autorun setting and (2) applications that are able to invoke other applications, as demonstrated by a file: URL specifying a .exe file. | 2 | 4.6 | Medium | 2017-01-03 | 2008-09-05 | View | |
4899 | CVE-2008-5115 | Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 allows remote attackers to hijack the authentication of administrators for requests that update the password via idm/admin/changeself.jsp. | 2 | 6.8 | Medium | 2017-01-03 | 2011-03-07 | View | |
70435 | CVE-2005-4846 | Format string vulnerability in Logger.cc for Spey 0.3.3 allows attackers to cause a denial of service (crash) and possibly execute arbitrary code via format string specifiers in a syslog call. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
5155 | CVE-2008-5377 | pstopdf in CUPS 1.3.8 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/pstopdf.log temporary file, a different vulnerability than CVE-2001-1333. | 2 | 6.9 | Medium | 2017-01-03 | 2009-01-06 | View |
Page 1274 of 17672, showing 5 records out of 88360 total, starting on record 6366, ending on 6370