NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
580  CVE-2008-0605  Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inject arbitrary web script or HTML via the (1) txtSearch parameter to operator/article/article_search_results.asp and the (2) Attach_Id parameter to operator/article/article_attachment.asp. NOTE: for vector 2, the XSS occurs in a forced SQL error message.    4.3  Medium  2017-01-03  2008-09-05  View
836  CVE-2008-0865  Unspecified vulnerability in BEA WebLogic Portal 8.1 through SP6 allows remote attackers to bypass entitlements for instances of a floatable WLP portlet via unknown vectors.    Medium  2017-01-03  2011-03-07  View
66372  CVE-2005-0621  Scrapland 1.0 and earlier allows remote attackers to cause a denial of service (server termination) by triggering an error, which is treated as a fatal error by the server, as demonstrated using (1) signed integers for size values, (2) an invalid model, (3) a "newpos" value that is less than or equal to a size value, or (4) partial packets.    Medium  2017-01-03  2016-10-17  View
1092  CVE-2008-1131  Cross-site scripting (XSS) vulnerability in Drupal 6.0 allows remote authenticated users to inject arbitrary web script or HTML via titles in content edit forms.    3.5  Low  2017-01-03  2008-09-05  View
1348  CVE-2008-1391  Multiple integer overflows in libc in NetBSD 4.x, FreeBSD 6.x and 7.x, and probably other BSD and Apple Mac OS platforms allow context-dependent attackers to execute arbitrary code via large values of certain integer fields in the format argument to (1) the strfmon function in lib/libc/stdlib/strfmon.c, related to the GET_NUMBER macro; and (2) the printf function, related to left_prec and right_prec.    7.5  High  2017-01-03  2016-12-06  View

Page 14478 of 17672, showing 5 records out of 88360 total, starting on record 72386, ending on 72390

Actions