NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 15430 | CVE-2010-4145 | Kisisel Radyo Script stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for sevvo/eco23.mdb. | 2 | 5 | Medium | 2017-01-18 | 2010-11-03 | View | |
| 15429 | CVE-2010-4144 | SQL injection vulnerability in radyo.asp in Kisisel Radyo Script allows remote attackers to execute arbitrary SQL commands via the Id parameter. | 2 | 7.5 | High | 2017-01-18 | 2010-11-03 | View | |
| 15428 | CVE-2010-4143 | SQL injection vulnerability in chart.php in phpCheckZ 1.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the id parameter. | 2 | 6.8 | Medium | 2017-01-18 | 2010-11-03 | View | |
| 15427 | CVE-2010-4142 | Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long (1) SCPC_INITIALIZE, (2) SCPC_INITIALIZE_RF, or (3) SCPC_TXTEVENT packet. NOTE: it was later reported that 1.06 is also affected by one of these requests. | 2 | 10 | High | 2017-01-18 | 2010-11-04 | View | |
| 15426 | CVE-2010-4121 | ** DISPUTED ** The TCP-to-ODBC gateway in IBM Tivoli Provisioning Manager for OS Deployment 7.1.1.3 does not require authentication for SQL statements, which allows remote attackers to modify, create, or read database records via a session on TCP port 2020. NOTE: the vendor disputes this issue, stating that the "default Microsoft Access database is not password protected because it is intended to be used for evaluation purposes only." | 2 | 7.5 | High | 2017-01-18 | 2010-10-29 | View |
Page 14587 of 17672, showing 5 records out of 88360 total, starting on record 72931, ending on 72935