NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
80584  CVE-2002-1631  SQL injection vulnerability in the query.xsql sample page in Oracle 9i Application Server (9iAS) allows remote attackers to execute arbitrary code via the sql parameter.    7.5  High  2017-01-05  2008-09-05  View
81096  CVE-2002-2145  Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders via a URL with a hex encoded space (%20) and a "." (%2e) at the end of the filename.    7.5  High  2017-01-05  2008-09-05  View
22728  CVE-2015-0231  Use-after-free vulnerability in the process_nested_data function in ext/standard/var_unserializer.re in PHP before 5.4.37, 5.5.x before 5.5.21, and 5.6.x before 5.6.5 allows remote attackers to execute arbitrary code via a crafted unserialize call that leverages improper handling of duplicate numerical keys within the serialized properties of an object. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-8142.    7.5  High  2017-01-19  2016-12-30  View
27336  CVE-2015-6401  Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspecified administrative functions via a crafted HTTP request, aka Bug ID CSCux24941.    7.5  High  2017-01-19  2015-12-14  View
29896  CVE-2014-10037  Directory traversal vulnerability in DomPHP 0.83 and earlier allows remote attackers to have unspecified impact via a .. (dot dot) in the url parameter to photoalbum/index.php.    7.5  High  2017-01-19  2015-01-14  View

Page 15063 of 17672, showing 5 records out of 88360 total, starting on record 75311, ending on 75315

Actions