NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 65862 | CVE-2005-0082 | The sapdbwa_GetUserData function in MySQL MaxDB 7.5.0.0, and other versions before 7.5.0.21, allows remote attackers to cause a denial of service (crash) via invalid parameters to the WebDAV handler code, which triggers a null dereference that causes the SAP DB Web Agent to crash. | 2 | 5 | Medium | 2017-01-03 | 2011-03-07 | View | |
| 45780 | CVE-2012-4388 | The sapi_header_op function in main/SAPI.c in PHP 5.4.0RC2 through 5.4.0 does not properly determine a pointer during checks for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1398. | 2 | 4.3 | Medium | 2017-01-19 | 2013-09-11 | View | |
| 8342 | CVE-2011-1398 | The sapi_header_op function in main/SAPI.c in PHP before 5.3.11 and 5.4.x before 5.4.0RC2 does not check for %0D sequences (aka carriage return characters), which allows remote attackers to bypass an HTTP response-splitting protection mechanism via a crafted URL, related to improper interaction between the PHP header function and certain browsers, as demonstrated by Internet Explorer and Google Chrome. | 2 | 4.3 | Medium | 2017-01-07 | 2013-10-10 | View | |
| 28927 | CVE-2015-8935 | The sapi_header_op function in main/SAPI.c in PHP before 5.4.38, 5.5.x before 5.5.22, and 5.6.x before 5.6.6 supports deprecated line folding without considering browser compatibility, which allows remote attackers to conduct cross-site scripting (XSS) attacks against Internet Explorer by leveraging (1) %0A%20 or (2) %0D%0A%20 mishandling in the header function. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
| 2425 | CVE-2008-2517 | The sarab.sh script in SaraB before 0.2.4 places the dar program"s encryption key on the command line, which allows local users to obtain sensitive information by listing the process. | 2 | 2.1 | Low | 2017-01-03 | 2011-03-07 | View |
Page 14425 of 17672, showing 5 records out of 88360 total, starting on record 72121, ending on 72125