NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
61225 | CVE-2006-2530 | avatar_upload.asp in Avatar MOD 1.3 for Snitz Forums 3.4, and possibly other versions, allows remote attackers to bypass file type checks and upload arbitrary files via a null byte in the file name, as discovered by the Codescan product. | 2 | 5 | Medium | 2016-12-20 | 2012-10-24 | View | |
61481 | CVE-2006-2796 | Cross-site scripting (XSS) vulnerability in gallery.php in Captivate 1.0 allows remote attackers to inject arbitrary web script or HTML via the page parameter, which is reflected in an error message. | 2 | 6.8 | Medium | 2016-12-20 | 2013-01-03 | View | |
62505 | CVE-2006-3837 | delcookie.php in Professional Home Page Tools Guestbook changes the expiration date of a cookie instead of deleting the cookie"s value, which makes it easier for attackers to steal the cookie and obtain the administrator"s password hash after logout. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
63273 | CVE-2006-4640 | Unspecified vulnerability in Adobe Flash Player before 9.0.16.0 allows user-assisted remote attackers to bypass the allowScriptAccess protection via unspecified vectors. | 2 | 6.8 | Medium | 2016-12-20 | 2011-03-07 | View | |
63785 | CVE-2006-5179 | Intoto iGateway VPN and iGateway SSL-VPN allow context-dependent attackers to cause a denial of service (CPU consumption) via parasitic public keys with large (1) "public exponent" or (2) "public modulus" values in X.509 certificates that require extra time to process when using RSA signature verification, a related issue to CVE-2006-2940. | 2 | 5.4 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 1520 of 17672, showing 5 records out of 88360 total, starting on record 7596, ending on 7600