NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
2962  CVE-2008-3074  The shellescape function in Vim 7.0 through 7.2, including 7.2a.10, allows user-assisted attackers to execute arbitrary code via the "!" (exclamation point) shell metacharacter in (1) the filename of a tar archive and possibly (2) the filename of the first file in a tar archive, which is not properly handled by the VIM TAR plugin (tar.vim) v.10 through v.22, as demonstrated by the shellescape, tarplugin.v2, tarplugin, and tarplugin.updated test cases. NOTE: this issue reportedly exists because of an incomplete fix for CVE-2008-2712. NOTE: this issue has the same root cause as CVE-2008-3075. NOTE: due to the complexity of the associated disclosures and the incomplete information related to them, there may be inaccuracies in this CVE description and in external mappings to this identifier.    9.3  High  2017-01-03  2010-08-21  View
68498  CVE-2005-2812  man2web allows remote attackers to execute arbitrary commands via -P arguments.    7.5  High  2017-01-03  2008-09-05  View
3218  CVE-2008-3337  PowerDNS Authoritative Server before 2.9.21.1 drops malformed queries, which might make it easier for remote attackers to poison DNS caches of other products running on other servers, a different issue than CVE-2008-1447 and CVE-2008-3217.    6.4  Medium  2017-01-03  2016-12-07  View
68754  CVE-2005-3091  Cross-site scripting (XSS) vulnerability in Mantis before 1.0.0rc1 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, as identified by bug#0005751 "thraxisp".    4.3  Medium  2017-01-03  2008-09-05  View
3474  CVE-2008-3604  SQL injection vulnerability in bannerclick.php in ZeeBuddy 2.1 allows remote attackers to execute arbitrary SQL commands via the adid parameter.    7.5  High  2017-01-03  2009-01-29  View

Page 15200 of 17672, showing 5 records out of 88360 total, starting on record 75996, ending on 76000

Actions