NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 53437 | CVE-2007-1234 | Multiple cross-site scripting (XSS) vulnerabilities in sitex allow remote attackers to inject arbitrary web script or HTML via (1) the sxYear parameter to calendar.php, (2) the search parameter to search.php, (3) the linkid parameter to redirect.php, or (4) the page parameter to calendar_events.php. | 2 | 4.3 | Medium | 2017-01-07 | 2009-03-12 | View | |
| 53693 | CVE-2007-1509 | Directory traversal vulnerability in enkrypt.php in Sascha Schroeder krypt (aka Holtstraeter Rot 13) allows remote attackers to read arbitrary files via a .. (dot dot) in the datei parameter. | 2 | 4.3 | Medium | 2017-01-07 | 2008-11-13 | View | |
| 55485 | CVE-2007-3333 | Stack-based buffer overflow in capture in IBM AIX 5.3 SP6 and 5.2.0 allows remote attackers to execute arbitrary code via a large number of terminal control sequences. | 2 | 6.9 | Medium | 2017-01-07 | 2011-08-04 | View | |
| 55741 | CVE-2007-3591 | Unspecified vulnerability in Profile.php in Elite Bulletin Board before 1.0.10 allows remote attackers to modify profile information via unspecified vectors related to "a remote form," probably related to direct requests and missing authorization checks. | 2 | 5 | Medium | 2017-01-07 | 2008-11-15 | View | |
| 55997 | CVE-2007-3853 | Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 and 10.2.0.3 allow remote authenticated users to have unknown impact via (1) DBMS_JAVA_TEST in the JavaVM component (DB01), (2) Oracle Text component (DB09), and (3) MDSYS.SDO_GEOR_INT in the Spatial component (DB15). NOTE: a reliable researcher claims that DB01 is SQL injection in DBMS_PRVTAQIS. | 2 | 6.5 | Medium | 2017-01-07 | 2012-10-22 | View |
Page 15328 of 17672, showing 5 records out of 88360 total, starting on record 76636, ending on 76640