NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
70356  CVE-2005-4767  BEA WebLogic Server and WebLogic Express 8.1 SP5 and earlier, and 7.0 SP6 and earlier, when using username/password authentication, does not lock out a username after the maximum number of invalid login attempts, which makes it easier for remote attackers to guess the password.    5.1  Medium  2017-01-03  2008-09-05  View
5076  CVE-2008-5298  chm2pdf 0.9 uses temporary files in directories with fixed names, which allows local users to cause a denial of service (chm2pdf failure) of other users by creating those directories ahead of time.    2.1  Low  2017-01-03  2011-02-04  View
70612  CVE-2004-0155  The KAME IKE Daemon Racoon, when authenticating a peer during Phase 1, validates the X.509 certificate but does not verify the RSA signature authentication, which allows remote attackers to establish unauthorized IP connections or conduct man-in-the-middle attacks using a valid, trusted X.509 certificate.    7.5  High  2016-12-20  2016-10-17  View
5332  CVE-2008-5583  Cross-site request forgery (CSRF) vulnerability in index.php in ProjectPier 0.8 and earlier allows remote attackers to perform actions as an administrator via the query string, as demonstrated by a delete project action.    6.8  Medium  2017-01-03  2009-01-29  View
5588  CVE-2008-5857  The DropDocuments plugin in KnowledgeTree before 3.5.4a allows remote authenticated users to gain administrative privileges via a certain sequence of "browse documents" and dashboard requests.    6.5  Medium  2017-01-03  2009-08-15  View

Page 15010 of 17672, showing 5 records out of 88360 total, starting on record 75046, ending on 75050

Actions