NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
65481  CVE-2006-6938  Directory traversal vulnerability in includes/common.php in NitroTech 0.0.3a, as distributed before 2006, allows remote attackers to include arbitrary files via ".." sequences in the root parameter.    Medium  2016-12-20  2011-03-07  View
202  CVE-2008-0217  The script program in FreeBSD 5.0 through 7.0-PRERELEASE invokes openpty, which creates a pseudo-terminal with world-readable and world-writable permissions when it is not run as root, which allows local users to read data from the terminal of the user running script.    6.9  Medium  2017-01-03  2008-09-05  View
65738  CVE-2006-7195  Cross-site scripting (XSS) vulnerability in implicit-objects.jsp in Apache Tomcat 5.0.0 through 5.0.30 and 5.5.0 through 5.5.17 allows remote attackers to inject arbitrary web script or HTML via certain header values.    4.3  Medium  2016-12-20  2011-03-07  View
458  CVE-2008-0480  Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary directories, and .txt and .zip files, via a .....\ in the sub parameter to (1) RTE_file_browser.asp or (2) file_browser.asp.    Medium  2017-01-03  2009-09-16  View
65994  CVE-2005-0230  Firefox 1.0 does not prevent the user from dragging an executable file to the desktop when it has an image/gif content type but has a dangerous extension such as .bat or .exe, which allows remote attackers to bypass the intended restriction and execute arbitrary commands via malformed GIF files that can still be parsed by the Windows batch file parser, aka "firedragging."    5.1  Medium  2017-01-03  2016-10-17  View

Page 15751 of 17672, showing 5 records out of 88360 total, starting on record 78751, ending on 78755

Actions