NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 68064 | CVE-2005-2372 | Oracle Forms 4.5 through 10g starts form executables from arbitrary directories and executes them as the Oracle or System user, which allows attackers to execute arbitrary code by uploading a malicious .fmx file and referencing it using an absolute pathname argument in the (1) form or (2) module parameters to f90servlet. | 2 | 7.2 | High | 2017-01-03 | 2016-10-17 | View | |
| 2784 | CVE-2008-2890 | Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) fflteam_id parameter to teams.php, the (2) league_id parameter to leagues.php, and the (3) player_id parameter to players.php. | 2 | 7.5 | High | 2017-01-03 | 2009-04-14 | View | |
| 68320 | CVE-2005-2631 | Cisco Clean Access (CCA) 3.3.0 to 3.3.9, 3.4.0 to 3.4.5, and 3.5.0 to 3.5.3 does not properly authenticate users when invoking API methods, which could allow remote attackers to bypass security checks, change the assigned role of a user, or disconnect users. | 2 | 7.5 | High | 2017-07-18 | 2017-07-10 | View | |
| 3040 | CVE-2008-3156 | The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and execute arbitrary cabinet (CAB) files via unspecified URLs passed to the Update method. | 2 | 9.3 | High | 2017-01-03 | 2011-03-07 | View | |
| 68576 | CVE-2005-2901 | Multiple Cross-site scripting (XSS) vulnerabilities in CjWeb2Mail 3.0 allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) message, or (3) ip parameter to thankyou.php or (4) emsg parameter to web2mail.php. | 2 | 4.3 | Medium | 2017-01-03 | 2016-10-17 | View |
Page 15150 of 17672, showing 5 records out of 88360 total, starting on record 75746, ending on 75750