NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
67586 | CVE-2005-1868 | I-Man 0.9, and possibly earlier versions, allows remote attackers to execute arbitrary PHP code by uploading a file attachment with a .php extension. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
2306 | CVE-2008-2390 | Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows remote attackers to execute arbitrary code via an absolute pathname in the first argument. | 2 | 6.8 | Medium | 2017-01-03 | 2012-10-29 | View | |
67842 | CVE-2005-2138 | Cross-site scripting (XSS) vulnerability in index.php in Comdev eCommerce 3.0 and 3.1 allows remote attackers to inject arbitrary web script or HTML via Javascript in the onMouseOver event of an "A" tag in a review message. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
2562 | CVE-2008-2664 | The rb_str_format function in Ruby 1.8.4 and earlier, 1.8.5 before 1.8.5-p231, 1.8.6 before 1.8.6-p230, 1.8.7 before 1.8.7-p22, and 1.9.0 before 1.9.0-2 allows context-dependent attackers to trigger memory corruption via unspecified vectors related to alloca, a different issue than CVE-2008-2662, CVE-2008-2663, and CVE-2008-2725. NOTE: as of 20080624, there has been inconsistent usage of multiple CVE identifiers related to Ruby. The CVE description should be regarded as authoritative, although it is likely to change. | 2 | 7.8 | High | 2017-01-03 | 2011-03-07 | View | |
68098 | CVE-2005-2406 | Opera 8.01 allows remote attackers to conduct cross-site scripting (XSS) attacks or modify which files are uploaded by tricking a user into dragging an image that is a "javascript:" URI. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View |
Page 140 of 17672, showing 5 records out of 88360 total, starting on record 696, ending on 700