NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 54894 | CVE-2007-2730 | Check Point ZoneAlarm Pro before 6.5.737.000 does not properly test for equivalence of process identifiers for certain Microsoft Windows API functions in the NT kernel 5.0 and greater, which allows local users to call these functions, and bypass firewall rules or gain privileges, via a modified identifier that is one, two, or three greater than the canonical identifier. | 2 | 7.2 | High | 2017-01-07 | 2008-11-15 | View | |
| 55918 | CVE-2007-3773 | Cross-site request forgery (CSRF) vulnerability in the Email-Template module in Generic YouTube Clone Script allows remote attackers to upload files with arbitrary file types to templates/emails/ as administrators. | 2 | 9.3 | High | 2017-01-07 | 2008-11-15 | View | |
| 56942 | CVE-2007-4831 | Multiple cross-site scripting (XSS) vulnerabilities in account_settings.php in TorrentTrader 1.07 allow remote attackers to inject arbitrary web script or HTML via the (1) avatar and (2) title parameters. | 2 | 2.6 | Low | 2017-01-07 | 2008-11-15 | View | |
| 57454 | CVE-2007-5389 | ** DISPUTED ** PHP remote file inclusion vulnerability in preview.php in the swMenuFree (com_swmenufree) 4.6 component for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. NOTE: a reliable third party disputes this issue because preview.php tests a certain constant to prevent direct requests. | 2 | 6.8 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 55919 | CVE-2007-3774 | Dvbbs 7.1.0 SP1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for Data/Dvbbs7.mdb. | 2 | 7.8 | High | 2017-01-07 | 2008-11-15 | View |
Page 15243 of 17672, showing 5 records out of 88360 total, starting on record 76211, ending on 76215