NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 80584 | CVE-2002-1631 | SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
| 81096 | CVE-2002-2145 | Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders via a URL with a hex encoded space (%20) and a "." (%2e) at the end of the filename. | 2 | 7.5 | High | 2017-01-05 | 2008-09-05 | View | |
| 22728 | CVE-2015-0231 | Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142. | 2 | 7.5 | High | 2017-01-19 | 2016-12-30 | View | |
| 27336 | CVE-2015-6401 | Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspecified administrative functions via a crafted HTTP request, aka Bug ID CSCux24941. | 2 | 7.5 | High | 2017-01-19 | 2015-12-14 | View | |
| 29896 | CVE-2014-10037 | Directory traversal vulnerability in DomPHP 0.83 and earlier allows remote attackers to have unspecified impact via a .. (dot dot) in the url parameter to photoalbum/index.php. | 2 | 7.5 | High | 2017-01-19 | 2015-01-14 | View |
Page 15063 of 17672, showing 5 records out of 88360 total, starting on record 75311, ending on 75315