NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
6849  CVE-2008-7118  WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain SQL query logs via a direct request for logs/cron.log.    Medium  2017-01-03  2009-08-28  View
72385  CVE-2004-2008  SQL injection vulnerability in modules.php in NukeJokes 1.7 and 2 Beta allows remote attackers to execute arbitrary SQL via the jokeid parameter.    4.6  Medium  2017-07-18  2017-07-10  View
7105  CVE-2017-3890  A reflected cross-site scripting vulnerability in the BlackBerry WatchDox Server components Appliance-X, version 1.8.1 and earlier, and vAPP, versions 4.6.0 to 5.4.1, allows remote attackers to execute script commands in the context of the affected browser by persuading a user to click an attacker-supplied malicious link.    4.3  Medium  2017-01-30  2017-01-20  View
72641  CVE-2004-2264  ** DISPUTED ** Format string bug in the open_altfile function in filename.c for GNU less 382, 381, and 358 might allow local users to cause a denial of service or possibly execute arbitrary code via format strings in the LESSOPEN environment variable. NOTE: since less is not setuid or setgid, then this is not a vulnerability unless there are plausible scenarios under which privilege boundaries could be crossed.    6.4  Medium  2017-07-18  2017-07-10  View
72897  CVE-2004-2520  POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (application crash) via a large numeric value in the (1) LIST, (2) RETR, or (3) UIDL commands.    Medium  2017-07-18  2017-07-10  View

Page 15445 of 17672, showing 5 records out of 88360 total, starting on record 77221, ending on 77225

Actions