NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 2986 | CVE-2008-3102 | Mantis 1.1.x through 1.1.2 and 1.2.x through 1.2.0a2 does not set the secure flag for the session cookie in an https session, which can cause the cookie to be sent in http requests and make it easier for remote attackers to capture this cookie. | 2 | 5 | Medium | 2017-01-03 | 2010-12-28 | View | |
| 3498 | CVE-2008-3629 | Apple QuickTime before 7.5.5 allows remote attackers to cause a denial of service (application crash) via a crafted PICT image that triggers an out-of-bounds read. | 2 | 4.3 | Medium | 2017-01-03 | 2013-11-02 | View | |
| 69034 | CVE-2005-3372 | Multiple interpretation error in eTrust CA 7.0.1.4 with the 11.9.1 engine allows remote attackers to bypass virus scanning via a file such as BAT, HTML, and EML with an "MZ" magic byte sequence which is normally associated with EXE, which causes the file to be treated as a safe type that could still be executed as a dangerous file type by applications on the end system, as demonstrated by a "triple headed" program that contains EXE, EML, and HTML content, aka the "magic byte bug." | 2 | 5.1 | Medium | 2017-01-03 | 2016-10-17 | View | |
| 69546 | CVE-2005-3908 | Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
| 69802 | CVE-2005-4204 | Cross-site scripting (XSS) vulnerability in LogiSphere 0.9.9j allows remote attackers to inject arbitrary Javascript via the msg command. NOTE: due to lack of appropriate details by the original researcher, it is unclear whether this issue is distinct from the msg DoS. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 14628 of 17672, showing 5 records out of 88360 total, starting on record 73136, ending on 73140