NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
31195  CVE-2014-2865  PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to bypass intended access restrictions via a "" character, as demonstrated by using this character within a pathname on the drive containing the web root directory of a ColdFusion installation.    7.5  High  2017-01-19  2014-04-16  View
31963  CVE-2014-3871  Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds and GeoAuctions) allow remote attackers to execute arbitrary SQL commands via the (1) c[password] or (2) c[username] parameter. NOTE: the b parameter to index.php vector is already covered by CVE-2006-3823.    7.5  High  2017-01-19  2015-09-29  View
40667  CVE-2013-5351  Heap-based buffer overflow in IrfanView before 4.37 allows remote attackers to execute arbitrary code via the LZW code stream in a GIF file.    7.5  High  2017-01-18  2014-03-16  View
43995  CVE-2012-2149  The WPXContentListener::_closeTableRow function in WPXContentListener.cpp in libwpd 0.8.8, as used by OpenOffice.org (OOo) before 3.4, allows remote attackers to execute arbitrary code via a crafted Wordperfect .WPD document that causes a negative array index to be used. NOTE: some sources report this issue as an integer overflow.    7.5  High  2017-01-19  2016-08-17  View
48603  CVE-2009-1316  Multiple SQL injection vulnerabilities in AbleSpace 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) eid parameter to events_view.php and the (2) id parameter to events_clndr_view.php.    7.5  High  2017-01-07  2009-04-28  View

Page 15303 of 17672, showing 5 records out of 88360 total, starting on record 76511, ending on 76515

Actions