NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 6831 | CVE-2008-7100 | Unspecified vulnerability in DotNetNuke 4.4.1 through 4.8.4 allows remote authenticated users to bypass authentication and gain privileges via unknown vectors related to a "unique id" for user actions and improper validation of a "user identity." | 2 | 6.5 | Medium | 2017-01-03 | 2009-08-28 | View | |
| 72367 | CVE-2004-1990 | Aldo's Web Server (aweb) 1.5 allows remote attackers to gain sensitive information via an arbitrary character, which reveals the full path and the user running the aweb process, possibly due to a malformed request. | 2 | 5 | Medium | 2017-07-18 | 2017-07-10 | View | |
| 72623 | CVE-2004-2246 | Cross-site scripting (XSS) vulnerability in Goollery before 0.04b allows remote attackers to inject arbitrary HTML or web script via the conversation_id parameter to viewpic.php. | 2 | 4.3 | Medium | 2016-12-20 | 2008-09-05 | View | |
| 7599 | CVE-2011-0539 | The key_certify function in usr.bin/ssh/key.c in OpenSSH 5.6 and 5.7, when generating legacy certificates using the -t command-line option in ssh-keygen, does not initialize the nonce field, which might allow remote attackers to obtain sensitive stack memory contents or make it easier to conduct hash collision attacks. | 2 | 5 | Medium | 2017-01-07 | 2016-12-07 | View | |
| 7855 | CVE-2011-0825 | Unspecified vulnerability in Oracle JD Edwards EnterpriseOne Tools 8.9 GA through 8.98.4.1 and OneWorld Tools through 24.1.3 allows remote attackers to affect confidentiality, integrity, and availability, related to Enterprise Infrastructure SEC. | 2 | 6.8 | Medium | 2017-01-07 | 2012-08-03 | View |
Page 14804 of 17672, showing 5 records out of 88360 total, starting on record 74016, ending on 74020