NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
70136  CVE-2005-4547  Cross-site scripting (XSS) vulnerability in home/search.php in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the q parameter, as used by the Keyword and Search fields.    4.3  Medium  2017-01-03  2008-09-20  View
69887  CVE-2005-4289  Cross-site scripting (XSS) vulnerability in EDCstore.pl in eDatCat 0.3 allows remote attackers to inject arbitrary web script or HTML via the user_action parameter.    4.3  Medium  2017-01-03  2008-09-20  View
3957  CVE-2008-4099  PyDNS (aka python-dns) before 2.3.1-4 in Debian GNU/Linux does not use random source ports or transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447.    6.4  Medium  2017-01-03  2008-09-19  View
3958  CVE-2008-4100  GNU adns 1.4 and earlier uses a fixed source port and sequential transaction IDs for DNS requests, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. NOTE: the vendor reports that this is intended behavior and is compatible with the product"s intended role in a trusted environment.    6.4  Medium  2017-01-03  2008-09-19  View
3982  CVE-2008-4126  PyDNS (aka python-dns) before 2.3.1-5 in Debian GNU/Linux does not use random source ports for DNS requests and does not use random transaction IDs for DNS retries, which makes it easier for remote attackers to spoof DNS responses, a different vulnerability than CVE-2008-1447. NOTE: this vulnerability exists because of an incomplete fix for CVE-2008-4099.    6.4  Medium  2017-01-03  2008-09-19  View

Page 15508 of 17672, showing 5 records out of 88360 total, starting on record 77536, ending on 77540

Actions