NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 67660 | CVE-2005-1945 | Cross-site scripting (XSS) vulnerability in the convert_highlite_words function in Invision Blog before 1.1.2 Final allows remote attackers to inject arbitrary web script or HTML via double hex encoded highlight data. | 2 | 4.3 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 2380 | CVE-2008-2469 | Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remote attackers to execute arbitrary code via a long DNS TXT record with a modified length field. | 2 | 10 | High | 2017-01-03 | 2011-03-07 | View | |
| 67916 | CVE-2005-2214 | apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords. | 2 | 4.6 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 2636 | CVE-2008-2742 | Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/config.php) in Achievo 1.2.0 through 1.3.2 allows remote attackers to execute arbitrary code by uploading a file with .php followed by a safe extension, then accessing it via a direct request to the file in the Achievo root directory. NOTE: this is only a vulnerability in environments that support multiple extensions, such as Apache with the mod_mime module enabled. | 2 | 7.5 | High | 2017-01-03 | 2009-04-14 | View | |
| 68172 | CVE-2005-2481 | ColdFusion Fusebox 4.1.0 allows remote attackers to obtain sensitive information via an invalid fuseaction parameter, which leaks the full server path in an error message, as demonstrated using the "?" (question mark) character. | 2 | 5 | Medium | 2017-01-03 | 2016-10-17 | View |
Page 14555 of 17672, showing 5 records out of 88360 total, starting on record 72771, ending on 72775