NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
54288  CVE-2007-2118  Unspecified vulnerability in the Upgrade/Downgrade component of Oracle Database 9.0.1.5 and 9.2.0.7 has unknown impact and attack vectors, aka DB13. NOTE: as of 20070424, Oracle has not disputed reliable claims that this is a buffer overflow involving the "mig utility."    7.5  High  2017-01-07  2012-10-22  View
54544  CVE-2007-2377  The Getahead Direct Web Remoting (DWR) framework 1.1.4 exchanges data using JavaScript Object Notation (JSON) without an associated protection scheme, which allows remote attackers to obtain the data via a web page that retrieves the data through a URL in the SRC attribute of a SCRIPT element and captures the data using other JavaScript code, aka "JavaScript Hijacking."    Medium  2017-01-07  2009-02-20  View
54800  CVE-2007-2636  Unspecified vulnerability in phpTodo before 0.8.1 allows remote attackers to have an unknown impact via newlines in regular expressions to (1) index.php, (2) feed.php, (3) prefs.php, and (4) todolist.php; and (5) classTodoItem.php and (6) phpTodoUser.php in libs/. NOTE: some of these details are obtained from third party information.    6.8  Medium  2017-01-07  2011-03-07  View
55056  CVE-2007-2896  Race condition in the Symantec Enterprise Security Manager (ESM) 6.5.3 managers and agents on Windows before 20070524 allows remote attackers to cause a denial of service (CPU consumption and application hang) via certain network scans to ESM ports.    4.3  Medium  2017-01-07  2011-03-07  View
55312  CVE-2007-3158  download_script.asp in ASP Folder Gallery allows remote attackers to read arbitrary files via a filename in the file parameter.    Medium  2017-01-07  2008-11-15  View

Page 1499 of 17672, showing 5 records out of 88360 total, starting on record 7491, ending on 7495

Actions