NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 70226 | CVE-2005-4637 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in Kayako SupportSuite 3.00.26 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) nav parameter in the downloads module, (2) Full Name and (3) Email fields in the core module, (4) Full Name, (5) Email, and (6) Subject fields in the tickets module, or (7) Registered Email field in the lostpassword feature in the core module. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-20 | View | |
| 4946 | CVE-2008-5162 | The arc4random function in the kernel in FreeBSD 6.3 through 7.1 does not have a proper entropy source for a short time period immediately after boot, which makes it easier for attackers to predict the function"s return values and conduct certain attacks against the GEOM framework and various network protocols, related to the Yarrow random number generator. | 2 | 6.9 | Medium | 2017-01-03 | 2008-12-03 | View | |
| 5202 | CVE-2008-5429 | Incredimail build 5853710 does not properly handle (1) multipart/mixed e-mail messages with many MIME parts and possibly (2) e-mail messages with many "Content-type: message/rfc822;" headers, which allows remote attackers to cause a denial of service (stack consumption or other resource consumption) via a large e-mail message, a related issue to CVE-2006-1173. | 2 | 4.3 | Medium | 2017-01-03 | 2009-01-29 | View | |
| 5458 | CVE-2008-5716 | xend in Xen 3.3.0 does not properly restrict a guest VM"s write access within the /local/domain xenstore directory tree, which allows guest OS users to cause a denial of service and possibly have unspecified other impact by writing to (1) console/tty, (2) console/limit, or (3) image/device-model-pid. NOTE: this issue exists because of erroneous set_permissions calls in the fix for CVE-2008-4405. | 2 | 7.2 | High | 2017-01-03 | 2009-01-06 | View | |
| 5714 | CVE-2008-5983 | Untrusted search path vulnerability in the PySys_SetArgv API function in Python 2.6 and earlier, and possibly later versions, prepends an empty string to sys.path when the argv[0] argument does not contain a path separator, which might allow local users to execute arbitrary code via a Trojan horse Python file in the current working directory. | 2 | 6.9 | Medium | 2017-01-03 | 2013-05-14 | View |
Page 14615 of 17672, showing 5 records out of 88360 total, starting on record 73071, ending on 73075