NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 69829 | CVE-2005-4231 | Cross-site scripting (XSS) vulnerability in Link Up Gold 2.5 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) link parameter to tell_friend.php, (2) phrase[] parameter to search.php in a search_links_advanced action, and the (3) direction or (4) sort parameter to articles.php. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
| 4549 | CVE-2008-4735 | PHP remote file inclusion vulnerability in header.php in Concord Asset, Software, and Ticket system (CoAST) 0.95 allows remote attackers to execute arbitrary PHP code via a URL in the sections_file parameter. | 2 | 8.5 | High | 2017-01-03 | 2008-10-24 | View | |
| 70085 | CVE-2005-4487 | Cross-site scripting (XSS) vulnerability in RAMSite R|1 CMS 1.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchfield parameter. | 2 | 4.3 | Medium | 2017-01-03 | 2011-03-07 | View | |
| 4805 | CVE-2008-5018 | The JavaScript engine in Mozilla Firefox 3.x before 3.0.4, Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via vectors related to "insufficient class checking" in the Date class. | 2 | 10 | High | 2017-01-03 | 2012-10-30 | View | |
| 70341 | CVE-2005-4752 | BEA WebLogic Server and WebLogic Express 8.1 SP4 and earlier, and 7.0 SP6 and earlier, might allow local users to gain privileges by using the run-as deployment descriptor element to change the privileges of a web application or EJB from the Deployer security role to the Admin security role. | 2 | 4.6 | Medium | 2017-01-03 | 2008-09-05 | View |
Page 15650 of 17672, showing 5 records out of 88360 total, starting on record 78246, ending on 78250