NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 3997 | CVE-2008-4141 | Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to execute arbitrary PHP code via a URL in the web_root parameter to (1) includes/function_core.php and (2) templates/layout_lyrics.php. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
| 4253 | CVE-2008-4428 | Unrestricted file upload vulnerability in upload.php in Phlatline"s Personal Information Manager (pPIM) 1.0 and earlier allows remote attackers to execute arbitrary code by uploading a .php file, then accessing it via a direct request to the file in the top-level directory. | 2 | 10 | High | 2017-01-03 | 2009-01-29 | View | |
| 4509 | CVE-2008-4695 | Opera before 9.60 allows remote attackers to obtain sensitive information and have unspecified other impact by predicting the cache pathname of a cached Java applet and then launching this applet from the cache, leading to applet execution within the local-machine context. | 2 | 9.3 | High | 2017-01-03 | 2011-03-07 | View | |
| 70045 | CVE-2005-4447 | SQL injection vulnerability in articlesarticles_funcs.php in phpCOIN 1.2.2 allows remote attackers to modify SQL syntax and possibly execute SQL in limited circumstances via the rec_next parameter. NOTE: the original disclosure suggests that command injection is not feasible because the injection occurs after an "ORDER BY" clause, but it is likely that this bug could result in an error message path disclosure due to a syntax error, in some environments. Therefore this is an exposure and should be included in CVE. | 2 | 7.5 | High | 2017-01-03 | 2008-09-05 | View | |
| 5021 | CVE-2008-5237 | Multiple integer overflows in xine-lib 1.1.12, and other 1.1.15 and earlier versions, allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via (1) crafted width and height values that are not validated by the mymng_process_header function in demux_mng.c before use in an allocation calculation or (2) crafted current_atom_size and string_size values processed by the parse_reference_atom function in demux_qt.c for an RDRF_ATOM string. | 2 | 10 | High | 2017-01-03 | 2009-08-26 | View |
Page 14608 of 17672, showing 5 records out of 88360 total, starting on record 73036, ending on 73040