NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
56160  CVE-2007-4028  Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote attackers to include and execute arbitrary local files via a full pathname in the site parameter. NOTE: some of these details are obtained from third party information.    7.5  High  2017-01-07  2008-11-15  View
56672  CVE-2007-4552  SQL injection vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary SQL commands via the blockpage parameter. NOTE: as of 20070827, the vendor has made conflicting statements regarding whether this issue exists or not.    7.5  High  2017-01-07  2008-11-15  View
57184  CVE-2007-5101  ChironFS before 1.0 RC7 sets user/group ownership to the mounter account instead of the creator account when files are created, which allows local users to gain privileges.    7.2  High  2017-01-07  2008-11-15  View
57696  CVE-2007-5633  Speedfan.sys in Alfredo Milani Comparetti SpeedFan 4.33, when used on Microsoft Windows Vista x64, allows local users to read or write arbitrary MSRs, and gain privileges and load unsigned drivers, via the (1) IOCTL_RDMSR 0x9C402438 and (2) IOCTL_WRMSR 0x9C40243C IOCTLs to Devicespeedfan, as demonstrated by an IOCTL_WRMSR action on MSR_LSTAR.    7.2  High  2017-01-07  2008-11-15  View
52321  CVE-2007-0089  jgbbs stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/bbs.mdb.    7.5  High  2017-01-07  2008-11-15  View

Page 15229 of 17672, showing 5 records out of 88360 total, starting on record 76141, ending on 76145

Actions