NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 3832 | CVE-2008-3970 | pam_mount 0.10 through 0.45, when luserconf is enabled, does not verify mountpoint and source ownership before mounting a user-defined volume, which allows local users to bypass intended access restrictions via a local mount. | 2 | 6.9 | Medium | 2017-01-03 | 2009-08-19 | View | |
| 69368 | CVE-2005-3730 | Multiple cross-site scripting (XSS) vulnerabilities in HTTPTranslatorServlet in Idetix Software Systems Revize CMS allow remote attackers to inject arbitrary web script or HTML via the (1) resourcetype, (2) objectmap, and (3) redirect parameters, possibly involving setWebSpace.jsp. | 2 | 4.3 | Medium | 2017-01-03 | 2008-09-05 | View | |
| 4088 | CVE-2008-4234 | Incomplete blacklist vulnerability in the Quarantine feature in CoreTypes in Apple Mac OS X 10.5 before 10.5.6 allows user-assisted remote attackers to execute arbitrary code via an executable file with the content type indicating no application association for the file, which does not trigger a "potentially unsafe" warning message. | 2 | 9.3 | High | 2017-01-03 | 2011-03-07 | View | |
| 69624 | CVE-2005-3986 | Multiple SQL injection vulnerabilities in Instant Photo Gallery 1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) cat_id parameter in portfolio.php and (2) cid parameter in content.php. | 2 | 7.5 | High | 2017-01-03 | 2011-03-07 | View | |
| 4344 | CVE-2008-4521 | SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module 2.0 for PHP-Fusion allows remote attackers to execute arbitrary SQL commands via the INFO_RAID_ID parameter. | 2 | 7.5 | High | 2017-01-03 | 2009-01-29 | View |
Page 14992 of 17672, showing 5 records out of 88360 total, starting on record 74956, ending on 74960