NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 56160 | CVE-2007-4028 | Absolute path traversal vulnerability in index.php in Webspell 4.01.02 allows remote attackers to include and execute arbitrary local files via a full pathname in the site parameter. NOTE: some of these details are obtained from third party information. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 56672 | CVE-2007-4552 | SQL injection vulnerability in index.php in Agares Media Arcadem 2.01 allows remote attackers to execute arbitrary SQL commands via the blockpage parameter. NOTE: as of 20070827, the vendor has made conflicting statements regarding whether this issue exists or not. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View | |
| 57184 | CVE-2007-5101 | ChironFS before 1.0 RC7 sets user/group ownership to the mounter account instead of the creator account when files are created, which allows local users to gain privileges. | 2 | 7.2 | High | 2017-01-07 | 2008-11-15 | View | |
| 57696 | CVE-2007-5633 | Speedfan.sys in Alfredo Milani Comparetti SpeedFan 4.33, when used on Microsoft Windows Vista x64, allows local users to read or write arbitrary MSRs, and gain privileges and load unsigned drivers, via the (1) IOCTL_RDMSR 0x9C402438 and (2) IOCTL_WRMSR 0x9C40243C IOCTLs to Devicespeedfan, as demonstrated by an IOCTL_WRMSR action on MSR_LSTAR. | 2 | 7.2 | High | 2017-01-07 | 2008-11-15 | View | |
| 52321 | CVE-2007-0089 | jgbbs stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for db/bbs.mdb. | 2 | 7.5 | High | 2017-01-07 | 2008-11-15 | View |
Page 15229 of 17672, showing 5 records out of 88360 total, starting on record 76141, ending on 76145