NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
439  CVE-2008-0461  SQL injection vulnerability in index.php in the Search module in PHP-Nuke 8.0 FINAL and earlier, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the sid parameter in a comments action to modules.php. NOTE: some of these details are obtained from third party information.    6.8  Medium  2017-01-03  2011-03-07  View
695  CVE-2008-0724  The Everything Development Engine in The Everything Development System Pre-1.0 and earlier stores passwords in cleartext in a database, which makes it easier for context-dependent attackers to obtain access to user accounts.    Medium  2017-01-03  2008-09-05  View
66231  CVE-2005-0474  SQL injection vulnerability in the user_valid_crypt function in user.php in WebCalendar 0.9.45 allows remote attackers to execute arbitrary SQL commands via an encoded webcalendar_session cookie.    6.4  Medium  2017-07-18  2017-07-10  View
951  CVE-2008-0988  Off-by-one error in the Libsystem strnstr API in libc on Apple Mac OS X 10.4.11 allows context-dependent attackers to cause a denial of service (crash) via crafted arguments that trigger a buffer over-read.    4.3  Medium  2017-01-03  2011-03-07  View
1207  CVE-2008-1248  The web interface on the central phone server for the Snom 320 SIP Phone allows remote attackers to make arbitrary phone calls via the "Call a number" field. NOTE: this might overlap CVE-2007-3440.    5.8  Medium  2017-01-03  2008-09-05  View

Page 15089 of 17672, showing 5 records out of 88360 total, starting on record 75441, ending on 75445

Actions