NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
72865  CVE-2004-2488  Directory traversal vulnerability in Nexgen FTP Server before 2.2.3.23 allows remote authenticated users to read or list arbitrary files via "C:" sequences in the (1) RETR (get), (2) NLST (ls), (3) LIST (ls), (4) RNFR, or (5) RNTO FTP commands.    Medium  2017-07-18  2017-07-10  View
74145  CVE-2003-1073  A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r argument with .. (dot dot) sequences in the job name, then modifying the directory structure after at checks permissions to delete the file and before the deletion actually takes place.    1.2  Low  2017-07-18  2017-07-10  View
80289  CVE-2002-1334  Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arbitrary web script as other users via (1) the direct parameter in imageFolio.cgi, or (2) nph-build.cgi.    6.8  Medium  2017-07-18  2017-07-10  View
81569  CVE-2017-3418  Vulnerability in the Oracle CRM Technical Foundation component of Oracle E-Business Suite (subcomponent: User Interface). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle CRM Technical Foundation. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle CRM Technical Foundation, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle CRM Technical Foundation accessible data as well as unauthorized update, insert or delete access to some of Oracle CRM Technical Foundation accessible data. CVSS v3.0 Base Score 8.2 (Confidentiality and Integrity impacts).    5.8  Medium  2017-02-15  2017-02-10  View
82593  CVE-2017-5998  Cross-site scripting (XSS) vulnerability in InterSect Alliance SNARE Epilog for UNIX version 1.5 allows remote authenticated users to inject arbitrary web script or HTML via the str_log_name parameter in a Web Admin Portal > Log Configuration > Add action.    3.5  Low  2017-02-28  2017-02-23  View

Page 1468 of 17672, showing 5 records out of 88360 total, starting on record 7336, ending on 7340

Actions