NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
29913  CVE-2014-1219  CA 2E Web Option r8.1.2 accepts a predictable substring of a W2E_SSNID session token in place of the entire token, which allows remote attackers to hijack sessions by changing characters at the end of this substring, as demonstrated by terminating a session via a modified SSNID parameter to web2edoc/close.htm.    5.1  Medium  2017-01-19  2014-02-21  View
57504  CVE-2007-5439  CA (formerly Computer Associates) eTrust ITM (Threat Manager) 8.1 stores sensitive user information in log files with predictable names, which allows remote attackers to obtain this information via unspecified vectors.    Medium  2017-01-07  2008-11-15  View
57329  CVE-2007-5253  c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName parameter in a GetImage action, by appending a NULL byte (%00) sequence followed by an image file extension, as demonstrated by a request for a ".txt%00.gif" file. NOTE: this might be a directory traversal vulnerability.    Medium  2017-01-07  2008-11-15  View
24229  CVE-2015-2058  c2s/c2s.c in Jabber Open Source Server 2.3.2 and earlier truncates data without ensuring it remains valid UTF-8, which allows remote authenticated users to read system memory or possibly have other unspecified impact via a crafted JID.    6.5  Medium  2017-01-19  2016-11-29  View
61806  CVE-2006-3126  c2faxrecv in capi4hylafax 01.02.03 allows remote attackers to execute arbitrary commands via null () and shell metacharacters in the TSI string, as demonstrated by a fax from an anonymous number.    7.5  High  2016-12-20  2011-03-07  View

Page 15389 of 17672, showing 5 records out of 88360 total, starting on record 76941, ending on 76945

Actions