NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
57898 | CVE-2007-5847 | Race condition in the CFURLWriteDataAndPropertiesToResource API in Core Foundation in Apple Mac OS X 10.4.11 creates files with insecure permissions, which might allow local users to obtain sensitive information. | 2 | 6.6 | Medium | 2017-01-07 | 2011-03-07 | View | |
58154 | CVE-2007-6147 | Multiple PHP remote file inclusion vulnerabilities in IAPR COMMENCE 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the (a) php_root_path and sometimes the (b) privilege_root_path parameter to various PHP scripts under (1) admin/includes/, (2) admin/phase/, (3) includes/, (4) includes/page_includes/, (5) reviewer/includes/, (6) reviewer/phase/, and (7) user/phase/. | 2 | 6.8 | Medium | 2017-01-07 | 2008-09-05 | View | |
59178 | CVE-2006-0440 | Text Rider 2.4 allows attackers to bypass authentication and upload files without providing a valid password by obtaining the MD5 hash of the password (possibly via another vulnerability that reads it from a data file), then including the hash in a cookie. | 2 | 5 | Medium | 2016-12-20 | 2008-09-05 | View | |
59434 | CVE-2006-0703 | Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulnerability involving the query string that is not quoted when inserted into style and body tags, as demonstrated using a bgcol parameter. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View | |
60202 | CVE-2006-1493 | Cross-site scripting (XSS) vulnerability in dir.php in Explorer XP allows remote attackers to inject arbitrary web script or HTML via the chemin parameter. NOTE: it is possible that this issue is resultant from CVE-2006-1492. | 2 | 4.3 | Medium | 2016-12-20 | 2011-03-07 | View |
Page 1551 of 17672, showing 5 records out of 88360 total, starting on record 7751, ending on 7755