NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
74394  CVE-2003-1324  Race condition in the can_open function in Elm ME+ 2.4, when installed setgid mail and the operating system lacks POSIX saved ID support, allows local users to read and modify certain files with the privileges of the mail group.    4.6  Medium  2017-01-03  2008-09-05  View
74650  CVE-2003-1580  The Apache HTTP Server 2.0.44, when DNS resolution is enabled for client IP addresses, uses a logging format that does not identify whether a dotted quad represents an unresolved IP address, which allows remote attackers to spoof IP addresses via crafted DNS responses containing numerical top-level domains, as demonstrated by a forged 123.123.123.123 domain name, related to an "Inverse Lookup Log Corruption (ILLC)" issue.    4.3  Medium  2017-01-03  2010-02-08  View
155  CVE-2008-0167  The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass intended access restrictions or have unspecified other impact in opportunistic circumstances.    4.6  Medium  2017-01-03  2011-03-07  View
411  CVE-2008-0433  PHP remote file inclusion vulnerability in theme/phpAutoVideo/LightTwoOh/sidebar.php in Agares phpAutoVideo 2.21 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the loadpage parameter, a different vector than CVE-2007-6614.    7.5  High  2017-01-03  2011-03-07  View
667  CVE-2008-0694  Cross-site scripting (XSS) vulnerability in the HTTP Server in IBM OS/400 V5R3M0 and V5R4M0 allows remote attackers to inject arbitrary web script or HTML via the Expect HTTP header.    4.3  Medium  2017-01-03  2011-03-07  View

Page 15275 of 17672, showing 5 records out of 88360 total, starting on record 76371, ending on 76375

Actions