NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
53590  CVE-2007-1406  Trac before 0.10.3.1 does not send a Content-Disposition HTTP header specifying an attachment in certain "unsafe" situations, which has unknown impact and remote attack vectors.    10  High  2017-01-07  2008-09-05  View
67851  CVE-2005-2147  Trac before 0.8.4 allows remote attackers to read or upload arbitrary files via a full pathname in the id parameter to the (1) upload or (2) attachment viewer scripts.    6.4  Medium  2017-01-03  2008-09-05  View
62363  CVE-2006-3695  Trac before 0.9.6 does not disable the "raw" or "include" commands when providing untrusted users with restructured text (reStructuredText) functionality from docutils, which allows remote attackers to read arbitrary files, perform cross-site scripting (XSS) attacks, or cause a denial of service via unspecified vectors. NOTE: this might be related to CVE-2006-3458.    6.8  Medium  2016-12-20  2011-03-16  View
46653  CVE-2012-5529  TraceManager in Firebird 2.5.0 and 2.5.1, when trace is enabled, allows remote authenticated users to cause a denial of service (NULL pointer dereference and crash) by preparing an empty dynamic SQL query.    3.5  Low  2017-01-19  2013-05-14  View
76558  CVE-2000-0315  traceroute in NetBSD 1.3.3 and Linux systems allows local unprivileged users to modify the source address of the packets, which could be used in spoofing attacks.    Medium  2017-01-05  2016-10-17  View

Page 15198 of 17672, showing 5 records out of 88360 total, starting on record 75986, ending on 75990

Actions