NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
79764  CVE-2002-0765  sshd in OpenSSH 3.2.2, when using YP with netgroups and under certain conditions, may allow users to successfully authenticate and log in with another user"s password.    7.5  High  2017-01-05  2008-09-10  View
16020  CVE-2010-4782  Multiple SQL injection vulnerabilities in list.asp in Softwebs Nepal (aka Ananda Raj Pandey) Ananda Real Estate 3.4 allow remote attackers to execute arbitrary SQL commands via the (1) city, (2) state, (3) country, (4) minprice, (5) maxprice, (6) bed, and (7) bath parameters, different vectors than CVE-2006-6807.    7.5  High  2017-01-18  2011-09-21  View
16276  CVE-2010-5041  SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary SQL commands via the id parameter in a plugin action.    7.5  High  2017-01-18  2011-11-16  View
82068  CVE-2016-7974  The IP parser in tcpdump before 4.9.0 has a buffer overflow in print-ip.c, multiple functions.    7.5  High  2017-02-08  2017-02-01  View
82580  CVE-2017-5344  An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist were implemented in a new class, SQLUtil (main/java/com/dotmarketing/common/util/SQLUtil.java), as part of the remediation of CVE-2016-8902; however, these can be overcome in the case of the q and inode parameters to the /categoriesServlet path. Overcoming these controls permits a number of blind boolean SQL injection vectors in either parameter. The /categoriesServlet web path can be accessed remotely and without authentication in a default dotCMS deployment.    7.5  High  2017-03-18  2017-03-06  View

Page 14484 of 17672, showing 5 records out of 88360 total, starting on record 72416, ending on 72420

Actions